{"id":"CVE-2026-28403","summary":"Textream Cross-Site WebSocket Hijacking (CSWSH) vulnerability","details":"Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:\u003chttpPort+1\u003e`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same browser session can silently connect to the local WebSocket server and send arbitrary `DirectorCommand` payloads, allowing full remote control of the teleprompter content. Version 1.5.1 fixes the issue.","aliases":["GHSA-wr3v-x247-337w"],"modified":"2026-08-12T03:51:10.738505349Z","published":"2026-03-02T15:45:18.206Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-346"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28403.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28403.json"},{"type":"ADVISORY","url":"https://github.com/f/textream/security/advisories/GHSA-wr3v-x247-337w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28403"},{"type":"FIX","url":"https://github.com/f/textream/commit/f5ebad82750b9313386c34af8f0ede50c213a8a0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/f/textream","events":[{"introduced":"0"},{"fixed":"3524fa96f98ba17025b48ce9e19d49d859fc2ec1"},{"fixed":"f5ebad82750b9313386c34af8f0ede50c213a8a0"}],"database_specific":{"cpe":"cpe:2.3:a:fka:textream:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.5.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.5.0","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.6","v1.3.5","v1.3.4","v1.3.3","v1.3.2","v1.3.1","v1.3.0","v1.2.4","v1.2.3","v1.2.1","v1.2.0","v1.1.0","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28403.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L"}]}