CVE-2026-24905General(linuxfoundation / inspektor_gadget)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is implemented in the file `inspektor-gadget/cmd/common/image/build.go`. The `Makefile.build` file is the Makefile template employed during the building process. This file includes user-controlled data in an unsafe fashion, specifically some parameters are embedded without an adequate escaping in the commands inside the Makefile. Prior to version 0.48.1, this implementation is vulnerable to command injection: an attacker able to control values in the `buildOptions` structure would be able to execute arbitrary commands during the building process. An attacker able to exploit this vulnerability would be able to execute arbitrary command on the Linux host where the `ig` command is launched, if images are built with the `--local` flag or on the build container invoked by `ig`, if the `--local` flag is not provided. The `buildOptions` structure is extracted from the YAML gadget manifest passed to the `ig image build` command. Therefore, the attacker would need a way to control either the full `build.yml` file passed to the `ig image build` command, or one of its options. Typically, this could happen in a CI/CD scenario that builds untrusted gadgets to verify correctness. Version 0.51.1 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • inspektor_gadget

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
inspektor_gadget

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-29: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-28: 101-2904-28
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-291
General1
2026-04-281
Disclosure1
Full discourse2 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24905: CVE-2026-24905: Command Injection in Inspektor Gadget Image Builder Inspektor Gadget versions prior to 0.48.1 contain a command injection vulnerability in the `ig image build` command. The parsing logic for the `build.yml` manifest fil... https://cvereports.com/reports/CVE-2026-24905

    Post summary

    CVE-2026-24905 is a disclosed command injection flaw in Inspektor Gadget <0.48.1's image build process, with no PoC, exploit, or mitigation noted in the brief announcement.

    0000027
    36 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24905 Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides… https://www.cve.org/CVERecord?id=CVE-2026-24905

    Post summary

    The post merely references CVE‑2026‑24905 and notes that Inspektor Gadget is a set of tools for Kubernetes and Linux hosts, without offering any exploit details, patches, or technical information.

    00000235
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationinspektor_gadget---

Explore more