AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 27 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts. | |
| Title | AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation | |
| First Time appeared |
Azuracast
Azuracast azuracast |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azuracast
Azuracast azuracast |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T01:28:48.450Z
Reserved: 2026-09-27T00:20:03.854Z
Link: CVE-2026-100857
No data.
Status : Received
Published: 2026-09-27T02:17:25.197
Modified: 2026-09-27T02:17:25.197
Link: CVE-2026-100857
No data.
OpenCVE Enrichment
No data.
Weaknesses