CVE-2026-100857 HIGH

CVE-2026-100857: AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation

Vendor Azuracast
Product AzuraCast
Weakness CWE-94 · Code injection
Published September 27, 2026
Last update September 27, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.

Key dates

02Disclosure timeline

September 27, 2026 CVE published

Related vulnerabilities

04Related CVE