Impact
AzuraCast versions prior to 0.23.6 allow authorized users with View station permissions to send requests to the Liquidsoap API endpoint. Because the endpoint lacks the RequireInternalConnection middleware and wrongfully interprets the presence of an AutoDJ header instead of a validated value, attackers can inject arbitrary now‑playing metadata. This capability enables the manipulation of broadcast content, the disruption of live streams, and the exposure of filesystem paths to the attacker.
Affected Systems
AzuraCast software running any version earlier than 0.23.6 is affected. The vulnerability applies to all deployments where the Liquidsoap API is exposed, regardless of operating system or hosting environment.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability carries moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be precisely quantified; however, the vulnerability is not currently listed in the CISA KEV catalog. An attacker requires legitimate credentials with at least View station permissions but can exploit the flaw from any network that can reach the Liquidsoap API, thereby enabling broadcast disruption and sensitive path disclosure.
OpenCVE Enrichment