CyberRota Analysis
AI-GeneratedAzuraCast versions prior to 0.23.4 are vulnerable to a code injection flaw that allows authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configurations. This vulnerability can lead to the execution of shell commands as the azuracast user, particularly through manipulated playlist URLs or metadata fields upon station restart. Organizations using AzuraCast should prioritize patching to mitigate the risk of unauthorized command execution.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration. Attackers can inject #{process.run()} expressions into playlist URLs or station metadata fields that execute shell commands as the azuracast user when the station restarts.