AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.
AzuraCast through 0.23.x Command Injection via Streamer Username
Problem type
Affected products
AzuraCast
<= 0.23.x - AFFECTED
References
https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf
https://www.vulncheck.com/advisories/azuracast-through-0.23-x-command-injection-via-streamer-username
GitHub Security Advisories
GHSA-cj27-w6j8-3fpw
AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config...
https://github.com/advisories/GHSA-cj27-w6j8-3fpwAzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.
https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf
https://nvd.nist.gov/vuln/detail/CVE-2026-100852
https://www.vulncheck.com/advisories/azuracast-through-0.23-x-command-injection-via-streamer-username
https://github.com/advisories/GHSA-cj27-w6j8-3fpw
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-100852Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-100852",
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"dateUpdated": "2026-09-27T01:28:45.077Z",
"dateReserved": "2026-09-27T00:18:40.972Z",
"datePublished": "2026-09-27T01:28:45.077Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck",
"dateUpdated": "2026-09-27T01:28:45.077Z"
},
"datePublic": "2026-08-07T00:00:00.000Z",
"title": "AzuraCast through 0.23.x Command Injection via Streamer Username",
"descriptions": [
{
"lang": "en",
"value": "AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes."
}
],
"affected": [
{
"vendor": "AzuraCast",
"product": "AzuraCast",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "0.23.x"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
"cweId": "CWE-78",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf",
"name": "GitHub Security Advisory (GHSA-73rf-jp3g-8rcf)",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://www.vulncheck.com/advisories/azuracast-through-0.23-x-command-injection-via-streamer-username",
"name": "VulnCheck Advisory: AzuraCast through 0.23.x Command Injection via Streamer Username",
"tags": [
"third-party-advisory"
]
}
],
"metrics": [
{
"format": "CVSS"
},
{
"format": "CVSS",
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
}
}
],
"credits": [
{
"lang": "en",
"value": "Alpastx",
"type": "reporter"
}
]
}
}
}