Azuracast · Azuracast · CVE-2026-100850
**Name of the Vulnerable Software and Affected Versions**
AzuraCast versions prior to 0.23.8
**Description**
An issue exists in the AutoDJ remote playlist fetch functionality within the `getMediaFromRemoteUrl()` function. A user with station Media permissions can create or update a playlist by setting `source` to `remote url` and `remote type` to `playlist`. By providing a `remote url` that points to a `file://` path or an internal, loopback, or link-local HTTP endpoint, the backend passes this URL directly to `file get contents()` without a scheme allowlist or private IP policy. This allows for server-side request forgery (SSRF) and local file read. The fetched content is parsed as M3U/PLS entries and returned via the `GET /api/station/{station id}/queue` endpoint to users with Broadcasting permissions, potentially disclosing sensitive host files such as `/etc/passwd` or the application `.env` file, as well as the bodies of internal HTTP requests.
**Recommendations**
Update AzuraCast to version 0.23.8 or later.
As a temporary mitigation, restrict the use of the `getMediaFromRemoteUrl()` function or limit the permissions for creating remote playlists until the update is applied.