Observed Signal · Sep 6, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Neutral
Security Market: Sonar DNS Field Command Injection Fixed by Developer
A developer discovered a command injection vulnerability in the DNS custom resolver field of Sonar, a macOS network scanning tool. The field, which accepts user input for custom DNS servers like Pi-hole or NextDNS, was passed to a privileged command without proper validation, potentially allowing arbitrary code execution as root. The fix involved allowlisting input to only accept valid IP addresses, passing arguments as an array instead of a shell string, and narrowing the privileged interface. The article also details three other security fixes made during a full pass: moving API tokens from a plist to the Keychain, preventing CSV export formula injection, and implementing atomic writes to avoid data corruption.
This is a security fix in a niche macOS app, relevant to the AdTech industry only as a general security best practice example, not a major platform event.
Key Takeaways & Evidence Grounding
- Sonar had a command injection vulnerability in its DNS resolver field.
- The vulnerability could allow running commands as root.
- The fix involves allowlisting IP addresses and using array arguments.
- API tokens were moved from preferences to Keychain.
- CSV export now prevents formula injection.
- Atomic writes prevent data loss from crashes.
Connected Companies & Entities
3 Entities mappedNextDNS
DNS-layer security and privacy filtering SaaS for users and organisations.
“The custom-resolver field exists because people run Pi-hole and NextDNS on their own networks....”
Sonar
Code quality and security software for engineering teams.
“Sonar has a Control tab. One of the things it does is switch the DNS resolver for your Mac....”
Cloudflare
Cloud platform for security, performance, and edge application delivery.
“tap Cloudflare, tap Quad9, or paste in the address of your own Pi-hole....”
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
