PT-2026-99470 · Azuracast · Azuracast

·

CVE-2026-100850

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AzuraCast versions prior to 0.23.8
Description An issue exists in the AutoDJ remote playlist fetch functionality within the getMediaFromRemoteUrl() function. A user with station Media permissions can create or update a playlist by setting source to remote url and remote type to playlist. By providing a remote url that points to a file:// path or an internal, loopback, or link-local HTTP endpoint, the backend passes this URL directly to file get contents() without a scheme allowlist or private IP policy. This allows for server-side request forgery (SSRF) and local file read. The fetched content is parsed as M3U/PLS entries and returned via the GET /api/station/{station id}/queue endpoint to users with Broadcasting permissions, potentially disclosing sensitive host files such as /etc/passwd or the application .env file, as well as the bodies of internal HTTP requests.
Recommendations Update AzuraCast to version 0.23.8 or later. As a temporary mitigation, restrict the use of the getMediaFromRemoteUrl() function or limit the permissions for creating remote playlists until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100850
GHSA-RRJX-WRHF-8V47

Affected Products

Azuracast