CVE-2026-24905 - Inspektor Gadget has a Command Injection vulnerability in
Makefile.build
CVE ID : CVE-2026-24905
Published : Jan. 29, 2026, 9:29 p.m. | 38 minutes ago
Description : Inspektor Gadget is a set of tools and framework for data collection and system inspectio...
CVE-2026-24905 - Inspektor Gadget has a Command Injection vulnerability in Makefile.build
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is implemented in the file `inspektor-gadget/cmd/common/image/build.go`. …