CVE-2026-25996Disclosure(linuxfoundation / inspektor_gadget)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are rendered to the terminal without any sanitization of control characters or ANSI escape sequences. Therefore, a maliciously forged – partially or completely – event payload, coming from an observed container, might inject the escape sequences into the terminal of ig operators, with various effects. The columns output mode is the default when running ig run interactively.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-150

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • inspektor_gadget

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
inspektor_gadget

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-04-28: 1Technical Details · 2026-02-13: 1Technical Details · 2026-04-28: 102-1202-1304-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-121
General1
2026-02-131
Disclosure1
2026-04-281
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25996 Inspektor Gadget Terminal Control Character Injection Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25996

    Post summary

    The text announces CVE-2026-25996, a terminal control character injection flaw in Inspektor Gadget, and links to a vulnerability details page.

    0001050
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25996 Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF … https://www.cve.org/CVERecord?id=CVE-2026-25996

    Post summary

    The text offers a brief mention of CVE-2026-25996 in relation to Inspektor Gadget but provides no technical depth or actionable security details.

    00010245
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25996: CVE-2026-25996: Terminal Escape Sequence Injection in Inspektor Gadget Inspektor Gadget versions prior to 0.49.1 are vulnerable to a Terminal Escape Sequence Injection (CWE-150) in the default columns output mode. The tool fails to san... https://cvereports.com/reports/CVE-2026-25996

    Post summary

    The text announces a new terminal escape sequence injection vulnerability in Inspektor Gadget, providing technical details but no PoC, exploit, or patch, and does not mention active exploitation.

    0000022
    36 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationinspektor_gadget---

Explore more