CVE-2026-42605
EUVD-2026-2893609.05.2026, 20:16
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem storage backend (the default), an authenticated user with media management permissions can write arbitrary files outside the station's media storage directory, achieving remote code execution by writing a PHP webshell to the web root. This issue has been patched in version 0.23.6.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| azuracast | azuracast | 𝑥 < 0.23.6 |
𝑥
= Vulnerable software versions
References