Junglewise Threat Intelligence

CVE-2026-100857: AzuraCast code injection in ConfigWriter via Liquidsoap string interpolation

CVE-2026-100857 · Severity: high · CVSS 8 · Published 2026-09-27

Technologies: AzuraCast. Vendors: AzuraCast.

Executive brief

AzuraCast is a web-based radio station management and streaming software. The vulnerability allows authenticated users with media or profile management permissions to inject malicious code that executes arbitrary shell commands on the server when a station configuration is restarted. An attacker could gain full control of the AzuraCast server and any systems it can access.

Technical details

The ConfigWriter::cleanUpString() method fails to sanitize Liquidsoap string interpolation sequences (#{...}), allowing code injection into station configuration files. Authenticated users with StationPermissions::Media or StationPermissions::Profile can inject #{process.run()} expressions into playlist URLs or metadata fields; when the station restarts, Liquidsoap evaluates these expressions and executes arbitrary shell commands as the azuracast user.

Affected products

  • AzuraCast AzuraCast before 0.23.4

Timeline

  • 2026-09-27: disclosed
  • 2026-09-27: patched: Version 0.23.4 released with fix

References

Related threats