CVE-2026-42605
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem storage backend (the default), an authenticated user with media management permissions can write arbitrary files outside the station's media storage directory, achieving remote code execution by writing a PHP webshell to the web root. This issue has been patched in version 0.23.6.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.03%
- Percentil entre todas las CVEs puntuadas: 62
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1505.003Web Shellpersistence90 % - Impacto secundario
T1005Data from Local Systemcollection75 % - Impacto secundario
T1059Command and Scripting Interpreterexecution85 %
Vulnerabilidad de path traversal (CWE-22) en endpoint remoto con PR:L que permite escribir webshell PHP en raíz web, logrando RCE. AV:N, PR:L → T1210. Impactos: webshell (T1505.003), ejecución de comandos y lectura de datos.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- https://github.com/AzuraCast/AzuraCast/commit/18c793b4427eb49e67a2fea99a89f1c9d9dd808d
- https://github.com/AzuraCast/AzuraCast/releases/tag/0.23.6
- https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-vp2f-cqqp-478j
- https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-vp2f-cqqp-478j
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-42605",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-42605",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-11T14:51:59.547374Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "AzuraCast",
"product": "AzuraCast",
"versions": [
{
"status": "affected",
"version": "< 0.23.6"
}
]
}
]
}
],
"published": "2026-05-09T20:16:30.020",
"references": [
{
"url": "https://github.com/AzuraCast/AzuraCast/commit/18c793b4427eb49e67a2fea99a89f1c9d9dd808d",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AzuraCast/AzuraCast/releases/tag/0.23.6",
"tags": [
"Product"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-vp2f-cqqp-478j",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-vp2f-cqqp-478j",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal sequences. When combined with a local filesystem storage backend (the default), an authenticated user with media management permissions can write arbitrary files outside the station's media storage directory, achieving remote code execution by writing a PHP webshell to the web root. This issue has been patched in version 0.23.6."
},
{
"lang": "es",
"value": "AzuraCast es una suite de gestión de radio web autoalojada y todo en uno. Antes de la versión 0.23.6, el parámetro de solicitud currentDirectory en el endpoint de carga de medios de Flow.js (POST /api/station/{station_id}/files/upload) no se sanea para secuencias de salto de ruta. Cuando se combina con un backend de almacenamiento de sistema de archivos local (el predeterminado), un usuario autenticado con permisos de gestión de medios puede escribir archivos arbitrarios fuera del directorio de almacenamiento de medios de la estación, logrando ejecución remota de código al escribir una webshell PHP en la raíz web. Este problema ha sido parcheado en la versión 0.23.6."
}
],
"lastModified": "2026-07-24T19:10:00.160",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:azuracast:azuracast:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "67379BAE-08E4-4D21-AFAD-27A6CD3F9DEC",
"versionEndExcluding": "0.23.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}