Impact
AzuraCast versions earlier than 0.23.6 are susceptible to a code injection flaw triggered via the remote relay password field. The vulnerability originates from incomplete migration from the legacy cleanUpString routine to toRawString, allowing attackers with RemoteRelays station permissions to inject Liquidsoap interpolation syntax. Successfully exploiting the flaw can lead to the execution of arbitrary code within the Liquidsoap process, disclosure of sensitive API keys, and disruption of station operations.
Affected Systems
AzuraCast platform, versions prior to 0.23.6. The flaw touches the remote relay password configuration used by stations that grant RemoteRelays permission.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is not available, but the lack of mitigation in public releases suggests that exploitation is possible if an attacker can obtain the required station permission. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to target a station with RemoteRelays permissions to inject the malicious Liquidsoap payload and achieve remote code execution.
OpenCVE Enrichment