Sceawere
Vulnerability Detail
CVE-2026-100852UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AzuraCast Command Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- AzuraCast
- Product
- AzuraCast
- Attack Type
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-27T02:17:24.437Z",
"pubdate": "2026-09-27T02:17:24.437Z",
"executiveSummary": "AzuraCast through version 0.23.x is susceptible to a command injection vulnerability within its Liquidsoap configuration generation module.\nThe vulnerability stems from improper neutralization of user-supplied input when generating live recording processes.\nAn authenticated user assigned the Streamers and Profile permissions can manipulate the streamer username field by injecting shell metacharacters.\nSuccessful exploitation allows for arbitrary command execution under the security context of the Liquidsoap process user.\nThis vulnerability poses a significant risk as it permits lateral movement or system compromise once the attacker achieves authenticated access to the station management interface.\nExploitation requires an authenticated session with specific administrative or streamer permissions, limiting the attack vector to insiders or compromised accounts.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure handling of the streamer username variable during the generation of the Liquidsoap configuration for live stream recording. In the affected versions of AzuraCast, the application utilizes process.run calls to manage recording operations but fails to properly sanitize or quote the user-provided streamer username.\nWhen a user with Streamers and Profile permissions modifies their account settings, they can input a malicious payload containing shell metacharacters (such as backticks, semicolons, or pipe operators) into the username field. Because the application logic inserts this variable directly into the shell-invoked command string without adequate escaping or parameterization, the operating system interprets the injected characters as part of the command execution sequence.\nThe attack flow proceeds as follows: First, the authenticated attacker updates their streamer username profile with a crafted string containing the command injection payload. Second, the attacker initiates a live stream or waits for a scheduled recording event. Third, the AzuraCast engine generates the Liquidsoap configuration, incorporating the malicious username into the system call responsible for recording initialization or termination. Finally, when the recording process closes, the underlying shell interprets the payload, executing the injected arbitrary commands with the privileges of the Liquidsoap service user.\nThis behavior facilitates a remote code execution scenario that can be leveraged to execute system commands, retrieve sensitive data from the host file system, or initiate reverse shells to provide further access to the underlying infrastructure. The vulnerability is highly dependent on the application's ability to trigger the process.run function post-configuration change, which occurs reliably during standard station operations involving live media broadcasts."
}