Executive brief
AzuraCast is a web-based radio station management and streaming software. The vulnerability allows authenticated users with media or profile management permissions to inject malicious code that executes arbitrary shell commands on the server when a station configuration is restarted. An attacker could gain full control of the AzuraCast server and any systems it can access.
Technical details
The ConfigWriter::cleanUpString() method fails to sanitize Liquidsoap string interpolation sequences (#{...}), allowing code injection into station configuration files. Authenticated users with StationPermissions::Media or StationPermissions::Profile can inject #{process.run()} expressions into playlist URLs or metadata fields; when the station restarts, Liquidsoap evaluates these expressions and executes arbitrary shell commands as the azuracast user.
Affected products
- AzuraCast AzuraCast before 0.23.4
Timeline
- 2026-09-27: disclosed
- 2026-09-27: patched: Version 0.23.4 released with fix