PatchSiren

zuraCast CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL zuraCast CVE published 2026-08-17

CVE-2026-67917

A SQL injection vulnerability exists in zuraCast versions up to and including 0.23.7. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without content validation or sanitization, allowing remote attackers to escalate privileges. This vulnerability is critical as it allows remote attackers to inject malicious SQL code and escalate privileges. Defenders responsible [truncated]