---
id: CVE-2026-100850
title: >-
  AzuraCast before 0.23.8 contains a server-side request forgery and local file
  read vulnerability in the AutoDJ remote playlist fetch
  (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl())
summary: >-
  AzuraCast before 0.23.8 contains a server-side request forgery and local file
  read vulnerability in the AutoDJ remote playlist fetch
  (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user
  with the station Media perm…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: AzuraCast
product: AzuraCast
affected:
  - AzuraCast < 0.23.8
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:24.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100850'
references:
  - url: >-
      https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-rrjx-wrhf-8v47
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/azuracast-before-0.23.8-ssrf-and-local-file-read-via-remote-playlist
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.577Z'
---

## Overview

AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url and remote_type=playlist whose remote_url points at a file:// path or an internal/loopback/link-local HTTP endpoint. When AutoDJ builds the queue, the backend passes the user-supplied URL directly to file_get_contents() with no scheme allowlist and no private/loopback/metadata IP policy (PHP allow_url_fopen is enabled by default, including in the Docker image). Lines from the fetched resource are parsed as M3U/PLS entries, stored in StationQueue.autodj_custom_uri, and returned by GET /api/station/{station_id}/queue to any user with the Broadcasting permission, disclosing host files readable by the web container (for example /etc/passwd or the application .env) and the bodies of non-blind internal HTTP requests. No patched version was available at the time of publication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
