CVE-2026-28403Disclosure(fka / textream)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fka textream systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same browser session can silently connect to the local WebSocket server and send arbitrary `DirectorCommand` payloads, allowing full remote control of the teleprompter content. Version 1.5.1 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • textream

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-04); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
textream

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0403-0503-06
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-041
Patch1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
Full discourse3 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28403 (CVSS:7.6, HIGH) is Analyzed. Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0...https://nvd.nist.gov/vuln/detail/CVE-2026-28403 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces a high‑severity CVE in Textream's DirectorServer WebSocket, stating the CVSS score but offering no PoC, exploit, or patch discussion.

    0000024
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28403 (CVSS:7.6, HIGH) is Analyzed. Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0...https://nvd.nist.gov/vuln/detail/CVE-2026-28403 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    This tweet announces CVE-2026-28403, noting its CVSS score and the affected Textream component before version 1.5.1, but it does not provide a PoC, exploit, mitigation, or active exploitation details.

    0000026
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A Cross-Site WebSocket Hijacking (CSWSH) vulnerability (CVE-2026-28403) affects `f/textream`. This flaw could lead to unauthorized session control. Apply the latest `Textream` update. #infosec #websocket #vulnerability https://www.pulsepatch.io/posts/cve-2026-28403-f-textream-cswsh-vulnerability

    Post summary

    The post announces a CSWSH vulnerability in Textream and urges users to apply the latest update, highlighting the patch as the key takeaway.

    0000036
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfkatextream---

Explore more