CVE-2026-100852 is a command injection vulnerability in AzuraCast before 0.23.8. Authenticated station users with Streamers and Profile permissions can exploit this vulnerability to execute commands as the Liquidsoap process user when recording closes. The vulnerability exists in the Liquidsoap config generation for live recording, where the streamer username is not properly quoted in process.run calls. T [truncated]
AzuraCast's Liquidsoap custom configuration fields are exposed through an endpoint lacking permission guarding. The PUT /api/station/{station_id}/profile/edit endpoint deserializes with GROUP_GENERAL annotation while requiring only StationPermissions::Profile, allowing station managers with profile permissions to write configuration typically reserved for broadcasting operators. This configuration is then [truncated]
CVE-2026-42606 is a high-severity vulnerability in AzuraCast’s ApplyXForwarded middleware that trusted the client-supplied X-Forwarded-Host header without a trusted-proxy allowlist. An unauthenticated attacker could influence the host used in a forgot-password email, poison the reset URL, and cause the reset token to be sent to an attacker-controlled destination when the victim clicked the link. With the [truncated]
CVE-2026-42605 affects AzuraCast before 0.23.6. An authenticated user with media management permissions can abuse unsanitized path input in the Flow.js upload endpoint to write files outside the intended media directory. On the default local filesystem storage backend, that can extend to remote code execution if a PHP file is written into the web root.