Loading market data...
← Back to CVE feed

CVE-2026-100856

HIGH CVSS 8.8 View on NVD ↗

Description

AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete migration from the vulnerable cleanUpString method to toRawString. Attackers with RemoteRelays station permission can inject nested Liquidsoap interpolation syntax to execute arbitrary code in the Liquidsoap process, disclose internal API keys, or disrupt station operation.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published: Sep 27, 2026 02:17 UTC Modified: Sep 27, 2026 02:17 UTC