Textream Cross-Site WebSocket Hijacking (CSWSH) vulnerability
Published Mar 2, 2026
7.6
HIGHCVSS 3.1
EPSS 0.18%
Description
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same browser session can silently connect to the local WebSocket server and send arbitrary `DirectorCommand` payloads, allowing full remote control of the teleprompter content. Version 1.5.1 fixes the issue.
Affected products
- Vendor n/a Product Textream Defaultunknown
Affected
- < 1.5.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Textream | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9200 Advisory
- https://github.com/f/textream/commit/f5ebad82750b9313386c34af8f0ede50c213a8a0 x_refsource_MISCPatch
- https://github.com/f/textream/security/advisories/GHSA-wr3v-x247-337w x_refsource_CONFIRMExploitMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9200 | Advisory | |
| https://github.com/f/textream/commit/f5ebad82750b9313386c34af8f0ede50c213a8a0 | x_refsource_MISCPatch | |
| https://github.com/f/textream/security/advisories/GHSA-wr3v-x247-337w | x_refsource_CONFIRMExploitMitigationVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data