CVE-2026-100857: AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AzuraCastto a version that resolves this vulnerability.Fixed in 0.23.4
Event History
Frequently Asked Questions
Which users can exploit this issue?
An attacker must be authenticated to AzuraCast and have either Media or Profile permissions. They can place malicious Liquidsoap interpolation expressions in playlist URLs or station metadata fields.
When does injected code execute, and under which account?
The injected Liquidsoap code executes when the affected station restarts. Shell commands run as the azuracast user.
Which deployments are affected?
AzuraCast versions before 0.23.4 are affected. The provided information does not identify any configuration prerequisite beyond allowing a user with Media or Profile permissions to modify the relevant station fields.