CVE-2026-28403 PUBLISHED

Textream Cross-Site WebSocket Hijacking (CSWSH) vulnerability

Assigner: GitHub_M
Reserved: 27.02.2026 Published: 02.03.2026 Updated: 02.03.2026

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the DirectorServer WebSocket server (ws://127.0.0.1:<httpPort+1>) accepts connections from any origin without validating the HTTP Origin header during the WebSocket handshake. A malicious web page visited in the same browser session can silently connect to the local WebSocket server and send arbitrary DirectorCommand payloads, allowing full remote control of the teleprompter content. Version 1.5.1 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
CVSS Score: 7.6

Product Status

Vendor f
Product textream
Versions
  • Version < 1.5.1 is affected

References

Problem Types

  • CWE-346: Origin Validation Error CWE