CVE-2026-100854 PUBLISHED

AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API

Assigner: VulnCheck
Reserved: 27.09.2026 Published: 27.09.2026 Updated: 27.09.2026

AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derives the AutoDJ flag from header presence rather than validated value. Users with View station permission can inject arbitrary now-playing metadata, disrupt live broadcasts, and disclose filesystem paths.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor AzuraCast
Product AzuraCast
Versions Default: unaffected
  • affected from 0 to 0.23.6 (excl.)
  • Version 0.23.6 is unaffected

Credits

  • offset reporter

References

Problem Types

  • Missing Authorization CWE