Sceawere
Vulnerability Detail
CVE-2026-100850UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AzuraCast SSRF and LFR Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.7
- Creation Date
- 1d ago
- Vendor
- AzuraCast
- Product
- AzuraCast
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url and remote_type=playlist whose remote_url points at a file:// path or an internal/loopback/link-local HTTP endpoint. When AutoDJ builds the queue, the backend passes the user-supplied URL directly to file_get_contents() with no scheme allowlist and no private/loopback/metadata IP policy (PHP allow_url_fopen is enabled by default, including in the Docker image). Lines from the fetched resource are parsed as M3U/PLS entries, stored in StationQueue.autodj_custom_uri, and returned by GET /api/station/{station_id}/queue to any user with the Broadcasting permission, disclosing host files readable by the web container (for example /etc/passwd or the application .env) and the bodies of non-blind internal HTTP requests. No patched version was available at the time of publication.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.7",
"pubDate": "2026-09-27T02:17:24.007Z",
"pubdate": "2026-09-27T02:17:24.007Z",
"executiveSummary": "AzuraCast versions prior to 0.23.8 are vulnerable to Server-Side Request Forgery (SSRF) and Local File Read (LFR) via the AutoDJ remote playlist fetch functionality. The vulnerability originates from insecure processing of user-supplied URLs in the backend/src/Radio/AutoDJ/QueueBuilder.php file.\nBy manipulating the 'remote_url' parameter when creating or updating a station playlist, an authenticated user with 'Media' permissions can force the application to fetch content from the 'file://' scheme or target internal/loopback/link-local network endpoints.\nThis flaw allows attackers to bypass security boundaries, potentially reading sensitive configuration files like '.env' or '/etc/passwd' from the web container, as well as interacting with internal network services otherwise unreachable from the outside. The retrieved content is subsequently exposed through the application's API to users with 'Broadcasting' permissions, facilitating data exfiltration. The risk is significant as it grants attackers local file access and network reconnaissance capabilities within the host environment. Exploitation requires authenticated access to the management interface with specific station permissions.",
"technicalDetails": "The vulnerability resides within the 'getMediaFromRemoteUrl()' method located in 'backend/src/Radio/AutoDJ/QueueBuilder.php'. The application fails to implement a scheme allowlist or an IP policy to filter prohibited addresses such as loopback (127.0.0.1/8), private (RFC 1918), or link-local (169.254.169.254) networks.\nWhen a user with 'Media' permissions submits a 'remote_url' via a playlist request, the backend directly passes this URL to the PHP 'file_get_contents()' function. Because the Docker environment retains the default PHP 'allow_url_fopen' configuration, the function interprets various wrappers. Specifically, the 'file://' wrapper allows the application to perform arbitrary file reads from the underlying container filesystem. By specifying a local path, an attacker can read system files or sensitive application environment variables, such as database credentials or encryption keys stored in '.env'.\nFurthermore, the absence of a blacklist for network destinations enables SSRF. An attacker can supply internal IP addresses or hostnames to probe internal services and metadata endpoints. The application processes the response of these requests as M3U/PLS entries and stores them in the 'StationQueue.autodj_custom_uri' field of the database.\nThe exploit chain concludes by leveraging the 'GET /api/station/{station_id}/queue' API endpoint. Any user with 'Broadcasting' permissions can query this endpoint to retrieve the stored queue content. Because the application blindly returns the parsed lines from the previously fetched resource, the sensitive information (file contents or internal HTTP response bodies) is exfiltrated and rendered directly in the API output. This bypasses typical access controls by leveraging the application's internal trust in the AutoDJ queue mechanism.\nThe scope of impact is limited to the web container's context, but given the nature of containerized deployments, this can facilitate further lateral movement or host reconnaissance. No explicit authentication for the target host is required, provided the attacker maintains valid credentials for the AzuraCast station management interface."
}