{"id":"CVE-2026-100852","published":"2026-09-27T02:17:24.437","lastModified":"2026-09-28T21:02:16.150","description":"AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf","tags":[]},{"url":"https://www.vulncheck.com/advisories/azuracast-through-0.23-x-command-injection-via-streamer-username","tags":[]},{"url":"https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf","tags":[]}],"exploitRefs":[{"url":"https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf","tags":[]},{"url":"https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows authenticated users with Streamers and Profile permissions to inject shell commands, leading to potential command execution as the Liquidsoap process user.","exploitability":"Exploitation requires the user to have Streamers and Profile permissions and to set a username containing shell metacharacters. The vulnerability is relatively easy to exploit given the required permissions.","blast_radius":"If exploited, this could lead to full control over the Liquidsoap process, potentially allowing attackers to disrupt the service or execute arbitrary commands.","remediation":"Upgrade to AzuraCast 0.23.8 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:04:10.883Z"}}