Impact
AzuraCast versions earlier than 0.23.4 contain a code injection flaw in ConfigWriter::cleanUpString() that fails to escape Liquidsoap string interpolation. An attacker who can authenticate and has Media or Profile permissions can inject Liquidsoap expressions such as #{process.run()} into playlist URLs or station metadata. When the station configuration is reloaded, the shell command is executed under the azuracast user, giving the attacker local code execution privileges. This flaw directly compromises the confidentiality, integrity, and availability of the host system.
Affected Systems
AzuraCast installations running any release before 0.23.4 are affected. The vulnerability is present in the core AzuraCast product; no specific sub‑components are listed beyond the factory configuration logic. Users should verify if their AzuraCast version predates 0.23.4.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog as of this analysis. The required attacker profile is an authenticated user with Media or Profile permissions, and the exploit requires the station to restart so that the malicious configuration is parsed. Given the lack of any publicly disclosed exploits, the current risk level is high but the exploitation probability is considered moderate due to the credential and context prerequisites.
OpenCVE Enrichment