๐Ÿ” CVE Alert

CVE-2026-24905

UNKNOWN 0.0

Inspektor Gadget has a Command Injection vulnerability in Makefile.build

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
28th

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is implemented in the file `inspektor-gadget/cmd/common/image/build.go`. The `Makefile.build` file is the Makefile template employed during the building process. This file includes user-controlled data in an unsafe fashion, specifically some parameters are embedded without an adequate escaping in the commands inside the Makefile. Prior to version 0.48.1, this implementation is vulnerable to command injection: an attacker able to control values in the `buildOptions` structure would be able to execute arbitrary commands during the building process. An attacker able to exploit this vulnerability would be able to execute arbitrary command on the Linux host where the `ig` command is launched, if images are built with the `--local` flag or on the build container invoked by `ig`, if the `--local` flag is not provided. The `buildOptions` structure is extracted from the YAML gadget manifest passed to the `ig image build` command. Therefore, the attacker would need a way to control either the full `build.yml` file passed to the `ig image build` command, or one of its options. Typically, this could happen in a CI/CD scenario that builds untrusted gadgets to verify correctness. Version 0.51.1 fixes the issue.

CWE CWE-77 CWE-78
Vendor inspektor-gadget
Product inspektor-gadget
Published Jan 29, 2026
Last Updated Apr 30, 2026
Stay Ahead of the Next One

Get instant alerts for inspektor-gadget inspektor-gadget

Be the first to know when new unknown vulnerabilities affecting inspektor-gadget inspektor-gadget are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

inspektor-gadget / inspektor-gadget
< 0.51.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/inspektor-gadget/inspektor-gadget/security/advisories/GHSA-79qw-g77v-2vfh github.com: https://github.com/inspektor-gadget/inspektor-gadget/commit/7c83ad84ff7a68565655253e2cf1c5d2da695c1a github.com: https://github.com/inspektor-gadget/inspektor-gadget/commit/d9bf2fe4a180dad33ce57ca793ff4799ee7b8320