Executive brief
AzuraCast is a self-hosted radio station management platform. A code injection vulnerability in the remote relay password field allows users with RemoteRelays station permission to inject and execute arbitrary code within the Liquidsoap audio streaming process, potentially exposing internal API keys or disrupting station broadcasts.
Technical details
The vulnerability exists in the ConfigWriter.php cleanUpString() method, which uses an ungreedy regex that can be bypassed via nested Liquidsoap interpolation syntax (#{#{EXPR}}). The password field was incompletely migrated from the vulnerable cleanUpString() to the safe toRawString() method during a prior patch. An attacker with RemoteRelays permission can inject nested interpolation syntax that bypasses the regex filter and executes arbitrary Liquidsoap code when the config is regenerated.
Affected products
- AzuraCast AzuraCast before 0.23.6
Timeline
- 2026-04-23: disclosed
- 2026-04-23: patched: version 0.23.6 released