High severity7.6NVD Advisory· Published Mar 2, 2026· Updated Jun 17, 2026
CVE-2026-28403
CVE-2026-28403
Description
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the DirectorServer WebSocket server (ws://127.0.0.1:<httpPort+1>) accepts connections from any origin without validating the HTTP Origin header during the WebSocket handshake. A malicious web page visited in the same browser session can silently connect to the local WebSocket server and send arbitrary DirectorCommand payloads, allowing full remote control of the teleprompter content. Version 1.5.1 fixes the issue.
Affected products
3- f/textreamv5Range: < 1.5.1
Patches
Vulnerability mechanics
References
2- github.com/f/textream/commit/f5ebad82750b9313386c34af8f0ede50c213a8a0nvdPatch
- github.com/f/textream/security/advisories/GHSA-wr3v-x247-337wnvdExploitMitigationVendor Advisory
News mentions
0No linked articles in our index yet.