Server-Side Request Forgery and Local File Read in AzuraCast by AzuraCast
CVE-2026-100850
4.8MEDIUM
What is CVE-2026-100850?
AzuraCast versions prior to 0.23.8 are impacted by a vulnerability that allows for server-side request forgery (SSRF) and local file reading. By utilizing the AutoDJ remote playlist feature, users with Media permissions can create or update playlists that include a remote URL pointing to a file or internal HTTP endpoint. This malicious action leads to the backend's direct use of user-supplied URLs without validating the scheme, exposing sensitive files within the web container, such as /etc/passwd, and internal HTTP request bodies. The vulnerability exists due to improper handling of URLs in the AutoDJ module, posing a significant risk of unauthorized file disclosure.
Affected Version(s)
AzuraCast 0 < 0.23.8
AzuraCast 0.23.8
