AzuraCast 在 0.23.8 版本之前存在服务器端请求伪造(SSRF)和本地文件读取漏洞。该漏洞位于 AutoDJ 的远程播放列表拉取功能中(具体文件为 backend/src/Radio/AutoDJ/QueueBuilder.php 中的 getMediaFromRemoteUrl() 函数)。拥有“站点媒体”(station Media)权限的用户可以创建或更新一个播放列表,将其 source 设置为 remote_url,remote_type 设置为 playlist,并将 remote_url
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100852 | 8.8 HIGH | AzuraCast before 0.23.8 Command Injection via Streamer Username |
| CVE-2026-100856 | 8.8 HIGH | AzuraCast before 0.23.6 Code Injection via Remote Relay Password |
| CVE-2026-100857 | 8.0 HIGH | AzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolation |
| CVE-2026-100851 | 7.6 HIGH | AzuraCast before 0.23.8 Broken Access Control via GET /api/station/{id}/vue/profile |
| CVE-2026-100847 | 7.5 HIGH | AzuraCast before 0.23.8 DQL Injection via sortOrder |
| CVE-2026-100849 | 7.1 HIGH | AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs |
| CVE-2026-100848 | 7.1 HIGH | AzuraCast before 0.23.8 Server-Side Request Forgery via Remote Relay URL |
| CVE-2026-100855 | 6.5 MEDIUM | AzuraCast before 0.23.6 Missing Permission Check via /play |
| CVE-2026-100854 | 6.3 MEDIUM | AzuraCast before 0.23.6 Metadata Injection via Liquidsoap API |
| CVE-2026-100853 | 5.9 MEDIUM | AzuraCast before 0.23.8 On-Demand Download Endpoint Authorization Bypass |
No comments yet