Junglewise Threat Intelligence

CVE-2026-100852: AzuraCast command injection in Liquidsoap config generation

CVE-2026-100852 · Severity: high · CVSS 8.8 · Published 2026-09-27

Technologies: AzuraCast. Vendors: AzuraCast.

Executive brief

AzuraCast is a web-based radio station management platform that generates configuration for the Liquidsoap audio streaming engine. Authenticated users with station Streamer and Profile permissions can inject shell metacharacters into their username and execute arbitrary operating system commands as the Liquidsoap process user when a live recording ends. This allows attackers to compromise the streaming infrastructure without requiring global administrator privileges.

Technical details

A command injection vulnerability exists in the Liquidsoap config generation for live recording (backend/src/Radio/Backend/Liquidsoap/ConfigWriter.php). The vulnerability arises from unsafe interpolation of the authenticated streamer username into a process.run call that moves recorded files, without using Liquidsoap's process.quote function. An authenticated attacker with Streamers and Profile permissions can set a username containing shell metacharacters, enable live stream recording, connect and disconnect from the DJ harbor, triggering command execution as the Liquidsoap/stations user when the on_close event fires.

Affected products

  • AzuraCast AzuraCast through 0.23.x

Timeline

  • 2026-09-27: disclosed
  • 2026-08-07: advisory: GitHub security advisory GHSA-73rf-jp3g-8rcf published

References

Related threats