High severity8.0NVD Advisory· Published Sep 27, 2026
CVE-2026-100857
CVE-2026-100857
Description
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.