Path traversal in AzuraCast - CVE-2026-42605

 

Path traversal in AzuraCast - CVE-2026-42605

Published: April 23, 2026


Vulnerability identifier: #VU127154
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42605
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to path traversal in the Flow.js media upload endpoint currentDirectory parameter when handling media upload requests. A remote user can upload a specially crafted file with traversal sequences in the currentDirectory parameter to execute arbitrary code.

Only instances using the local filesystem storage backend are vulnerable, and media management permissions are required.


Affected software

AzuraCast

How to mitigate CVE-2026-42605

Install security update from vendor's website.

AzuraCast - update to 0.23.5

External References

Related Security Bulletins