Executive brief
Netatalk is an open-source implementation of the Apple Filing Protocol (AFP) used to provide file services for Apple Macintosh computers. A security flaw in how the software handles storage volume paths could allow an administrator or a user with high-level system access to execute unauthorized commands on the server. While this requires existing high-level access to the configuration, it could lead to a full system takeover or persistent unauthorized access.
Technical details
A shell injection vulnerability (CWE-78) exists in Netatalk's Spotlight service setup. The root cause is the improper neutralization of administrator-configured volume paths when they are embedded into single-quoted shell commands. An attacker with high privileges (PR:H) who can influence the configuration files can inject arbitrary OS commands that execute when the service starts or reconfigures. The attack vector is local (AV:L), meaning it cannot be exploited remotely via the AFP protocol alone. The issue is fixed in version 4.4.3 or by applying a specific security patch to version 4.4.2.
Affected products
- Netatalk Netatalk 3.1.0 through 4.4.2
Timeline
- 2026-05-13: disclosed: Initial disclosure date
- 2026-05-21: advisory: NVD publication date
- 2026-05-21: patched: Fixed in version 4.4.3