Sceawere
Vulnerability Detail
CVE-2026-100856UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AzuraCast Remote Relay Code Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- AzuraCast
- Product
- AzuraCast
- Attack Type
- Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-27T02:17:25.050Z",
"pubdate": "2026-09-27T02:17:25.050Z",
"executiveSummary": "AzuraCast versions prior to 0.23.6 are susceptible to a critical code injection vulnerability within the remote relay password configuration field. This flaw arises from an incomplete migration of input sanitization logic, specifically the transition from the legacy cleanUpString method to the more secure toRawString function. The vulnerability allows authenticated users possessing 'RemoteRelays' station permissions to inject malicious Liquidsoap interpolation syntax into the system configuration.\nBy leveraging this injection vector, an attacker can achieve arbitrary code execution within the context of the Liquidsoap process. The potential impact is severe, encompassing the unauthorized disclosure of sensitive internal API keys, complete disruption of station operations, and potential compromise of the underlying broadcast infrastructure. Exploitation requires authenticated access to the AzuraCast web interface with specific station management privileges. Given the capacity for arbitrary command execution, this vulnerability poses a significant risk to the integrity and confidentiality of the broadcast environment, necessitating immediate patching to the latest stable version.",
"technicalDetails": "The vulnerability is localized to the handling of the remote relay password field within the AzuraCast codebase. The root cause is an inconsistent application of input filtering mechanisms. Historically, the application utilized the cleanUpString method to process user-supplied configuration data; however, this method proved insufficient in neutralizing specific control characters and syntax used by the Liquidsoap streaming engine. Although the developers initiated a migration to the more robust toRawString function to sanitize inputs, this migration was incomplete, leaving the remote relay password field exposed.\nThe attack flow begins when an attacker, already possessing the 'RemoteRelays' permission, navigates to the station configuration interface. By crafting a malicious payload containing nested Liquidsoap interpolation syntax (typically using '${...}' sequences), the attacker bypasses the remaining weak sanitization filters. When the AzuraCast system processes this configuration and pushes the updated parameters to the Liquidsoap backend, the injected code is interpreted and executed by the Liquidsoap process.\nLiquidsoap, being a powerful language for audio stream processing, executes the injected directives with the privileges of the system process running the broadcast. This allows the attacker to manipulate the stream, extract configuration variables stored in memory—including internal API keys and credentials—or terminate the broadcast process entirely. Since the remote relay configuration is persistent and dynamically loaded into the process environment, the payload can be triggered upon subsequent reloads or configuration updates.\nThis vulnerability is classified as a code injection flaw due to the improper neutralization of special elements used in a command-line or interpreted language. The failure to fully deprecate the vulnerable cleanUpString method in favor of toRawString creates a logical discrepancy where specific fields are treated as trusted input despite containing executable script characters. The security impact is magnified by the fact that Liquidsoap often requires direct access to audio devices and network sockets, providing the attacker with a bridge to further interact with the host operating system if the process isolation is not strictly enforced."
}