Sceawere

Vulnerability Detail

CVE-2026-100857UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AzuraCast Liquidsoap Code Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8
Creation Date
1d ago
Vendor
AzuraCast
Product
AzuraCast
Attack Type
Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.0",
  "pubDate": "2026-09-27T02:17:25.197Z",
  "pubdate": "2026-09-27T02:17:25.197Z",
  "executiveSummary": "AzuraCast versions prior to 0.23.4 are susceptible to a code injection vulnerability arising from insufficient input sanitization within the ConfigWriter::cleanUpString() method.\nThe vulnerability allows authenticated users possessing at least Media or Profile permissions to inject arbitrary Liquidsoap string interpolation sequences into configuration parameters, such as playlist URLs or station metadata fields.\nBy weaponizing the #{process.run()} directive, an attacker can achieve Remote Code Execution (RCE) on the underlying host system, executing shell commands with the privileges of the azuracast user account.\nThe exploit is triggered during the station configuration update cycle, specifically when the Liquidsoap process parses the contaminated configuration files upon a station restart.\nThis vulnerability poses a critical risk to system integrity and confidentiality, as it facilitates unauthorized system interaction and potential persistence within the hosting environment.\nThe exploitation requirement is restricted to authenticated users with specific media management or profile editing privileges, thereby limiting the initial attack surface to authorized entities or compromised low-privileged accounts.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper handling of user-supplied input within the ConfigWriter::cleanUpString() function, which serves as a critical sanitizer for data destined for Liquidsoap configuration files.\nThe implementation fails to neutralize or escape Liquidsoap-specific string interpolation syntax, specifically the #{...} sequence, which is interpreted by the Liquidsoap engine as executable code when processed during the station generation phase.\nThe vulnerability manifests when user-controlled fields, such as playlist URLs or station metadata, are persisted to the database and subsequently utilized by the ConfigWriter class to generate the Liquidsoap configuration files.\nAn attacker with Media or Profile permissions can inject a payload containing the #{process.run('command_here')} syntax into these fields. Because the input is not sanitized, the malicious string is written directly into the generated .liq configuration file.\nThe attack flow proceeds as follows: First, the attacker updates a field—such as a playlist URL—with a payload designed to execute a system command. Second, the attacker triggers a station restart within the AzuraCast interface. Third, the ConfigWriter class compiles the configuration, incorporating the malicious string into the output.\nUpon the subsequent reload or restart, the Liquidsoap process executes the injected #{process.run()} sequence. This results in the underlying operating system executing the specified command with the security context and permissions of the azuracast system user.\nThe technical impact of this vulnerability is significant, as it effectively bridges the gap between application-layer data entry and operating system command execution. By escaping the application sandbox, the attacker can interact with the host file system, network, and local processes.\nPost-exploitation activities are bounded by the permissions of the azuracast user, which are typically sufficient to facilitate internal network scanning, lateral movement within the container or host, and the potential exfiltration of sensitive configuration files, stream keys, or environment variables containing credentials."
}
CVE-2026-100857: AzuraCast Liquidsoap Code Injection Vulnerability (HIGH Severity, CVSS: 8.0) | Sceawere