PT-2026-99476 · Azuracast · Azuracast
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AzuraCast versions prior to 0.23.6
Description
Code injection is possible due to an incomplete migration from the
cleanUpString method to toRawString. Users with RemoteRelays station permissions can inject nested Liquidsoap interpolation syntax into the remote relay password field. This allows for arbitrary code execution within the Liquidsoap process, disclosure of internal API keys, or disruption of station operations.Recommendations
Update to version 0.23.6 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azuracast