Path traversal in AzuraCast - CVE-2026-42605
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to path traversal in the Flow.js media upload endpoint currentDirectory parameter when handling media upload requests. A remote user can upload a specially crafted file with traversal sequences in the currentDirectory parameter to execute arbitrary code.
Only instances using the local filesystem storage backend are vulnerable, and media management permissions are required.