CVE-2026-100857
Severity CVSS v4.0:
HIGH
Type:
CWE-94
Code Injection
Publication date:
27/09/2026
Last modified:
27/09/2026
Description
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.00
Severity 3.x
HIGH


