PT-2026-99470 · Azuracast · Azuracast
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AzuraCast versions prior to 0.23.8
Description
An issue exists in the AutoDJ remote playlist fetch functionality within the
getMediaFromRemoteUrl() function. A user with station Media permissions can create or update a playlist by setting source to remote url and remote type to playlist. By providing a remote url that points to a file:// path or an internal, loopback, or link-local HTTP endpoint, the backend passes this URL directly to file get contents() without a scheme allowlist or private IP policy. This allows for server-side request forgery (SSRF) and local file read. The fetched content is parsed as M3U/PLS entries and returned via the GET /api/station/{station id}/queue endpoint to users with Broadcasting permissions, potentially disclosing sensitive host files such as /etc/passwd or the application .env file, as well as the bodies of internal HTTP requests.Recommendations
Update AzuraCast to version 0.23.8 or later.
As a temporary mitigation, restrict the use of the
getMediaFromRemoteUrl() function or limit the permissions for creating remote playlists until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azuracast