PT-2026-22625 · Textream · Textream

Iamcanturk

·

Published

2026-03-02

·

Updated

2026-03-06

·

CVE-2026-28403

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Textream versions prior to 1.5.1
Description The application is a macOS teleprompter. A Cross-Site WebSocket Hijacking (CSWSH) condition exists in the DirectorServer WebSocket server (ws://127.0.0.1:<httpPort+1>). The server does not validate the HTTP Origin header during the WebSocket handshake, allowing connections from any origin. A malicious web page, accessed during the same browser session, can connect to the WebSocket server and send arbitrary DirectorCommand payloads, enabling full remote control of the teleprompter content.
Recommendations Update to version 1.5.1 or later.

Exploit

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-28403
GHSA-WR3V-X247-337W

Affected Products

Textream