Junglewise Threat Intelligence

CVE-2026-100856: AzuraCast code injection in remote relay password field

CVE-2026-100856 · Severity: high · CVSS 8.8 · Published 2026-09-27

Technologies: AzuraCast. Vendors: AzuraCast.

Executive brief

AzuraCast is a self-hosted radio station management platform. A code injection vulnerability in the remote relay password field allows users with RemoteRelays station permission to inject and execute arbitrary code within the Liquidsoap audio streaming process, potentially exposing internal API keys or disrupting station broadcasts.

Technical details

The vulnerability exists in the ConfigWriter.php cleanUpString() method, which uses an ungreedy regex that can be bypassed via nested Liquidsoap interpolation syntax (#{#{EXPR}}). The password field was incompletely migrated from the vulnerable cleanUpString() to the safe toRawString() method during a prior patch. An attacker with RemoteRelays permission can inject nested interpolation syntax that bypasses the regex filter and executes arbitrary Liquidsoap code when the config is regenerated.

Affected products

  • AzuraCast AzuraCast before 0.23.6

Timeline

  • 2026-04-23: disclosed
  • 2026-04-23: patched: version 0.23.6 released

References

Related threats