---
id: CVE-2026-100852
title: >-
  AzuraCast through 0.23.x contains a command injection vulnerability in the
  Liquidsoap config generation for live recording that fails to quote the
  streamer username in process.run calls
summary: >-
  AzuraCast through 0.23.x contains a command injection vulnerability in the
  Liquidsoap config generation for live recording that fails to quote the
  streamer username in process.run calls. Authenticated station users with
  Streamers and Pro…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: AzuraCast
product: AzuraCast
affected:
  - AzuraCast <= 0.23.x
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T02:17:24.437'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100852'
references:
  - url: >-
      https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-73rf-jp3g-8rcf
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/azuracast-through-0.23-x-command-injection-via-streamer-username
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T02:41:45.578Z'
---

## Overview

AzuraCast through 0.23.x contains a command injection vulnerability in the Liquidsoap config generation for live recording that fails to quote the streamer username in process.run calls. Authenticated station users with Streamers and Profile permissions can set a username containing shell metacharacters and trigger command execution as the Liquidsoap process user when recording closes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
