Skip to content
Textual
Menu

Historical security advisories

The 2016 and 2017 advisories, preserved with their original affected-version context.

A reference from an earlier chapter

This material preserves the original Textual documentation and may describe older versions, former services, or superseded policies. It is not a statement of current availability or new Blendbyte commitments.

On this page

These reports concern earlier releases. Use the current supported download rather than following an old emergency workaround on a modern installation. Code examples are shown as text.

Security Advisory: January 2016, #1

Summary

A vulnerability was discovered that allowed JavaScript to be injected into the HTML view that renders channel content.

Codeux Software is not aware of any case in which this vulnerability was abused in the wild.

Details

The vulnerability, which was discovered by Wladimir Palant, has existed since version 2.1.1 (mid-2012) of Textual.

Double quotes (") are allowed to appear inside a URL which means a person with malicious intent had the power to append code to the HTML anchor element which is used to turn a URL into a link.

The vulnerability was fixed by appropriately escaping the characters inside each URL.

Proof of Concept

This web page will be displayed to anyone who hovers their mouse pointer over the URL displayed below.

https://bing.com/#"onmouseover="eval(atob('d2luZG93LmxvY2F0aW9uPSdodHRwczovL2hlbHAuY29kZXV4LmNvbS90ZXh0dWFsL1NlY3VyaXR5LUFkdmlzb3J5LUphbnVhcnktMjAxNi0xLmtiJzs='))

This works by decoding the encoded data and evaluating it as JavaScript.

The encoded data, when decoded, is:

window.location='https://textualapp.com/docs/legacy/security/advisories';

Security Advisory: October 2017, #1

Overview

Users that are running version 7.0.5 of Textual or an earlier version are advised to update to version 7.0.6 immediately.

Your personal information is NOT at risk. The bug that was patched by version 7.0.6 caused users to be banned from servers for unintentional private message spam. That is the worst that can happen.

This is a preliminary advisory. More information will be available at a later date.

Standalone Version

If you are running the standalone version of Textual, then follow these steps to update:

  • Navigate to the main menu in the top left corner of your screen

  • Click the bold menu labeled “Textual” next to the Apple symbol ()

  • In the menu that appears, click “Check for updates…”

Mac App Store Version

If you are running the Mac App Store version of Textual, then see the Updates section of the store.

Hidden Preference

If you are unable to update to version 7.0.6 of Textual, then you can permanently disable the Off-the-Record (OTR) Messaging feature to work around the bug.

To disable this feature, follow these steps:

  1. Open the application named Terminal using Spotlight.

Archived Textual screenshot

  1. Once opened, copy and paste one of the following commands, then press Return.

If you aren't sure which to copy and paste, it is safe to do both.

Standalone Version

defaults write com.codeux.apps.textual \
"Off-the-Record Messaging -> Enable Encryption" -bool NO

Mac App Store Version

defaults write 8482Q6EPL6.com.codeux.irc.textual \
"Off-the-Record Messaging -> Enable Encryption" -bool NO
Source material

Original Codeux material preserved from the knowledgebase snapshot of 9 September 2026. Formatting and internal links have been adapted for this site.

Need a hand? Contact us about this guide.

Textual screenshot