PT-2026-7900 · Unknown · Inspektor-Gadget

Ndaprela

+1

·

Published

2026-02-12

·

Updated

2026-04-28

·

CVE-2026-25996

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Inspektor Gadget (affected versions not specified)
Description Inspektor Gadget has an issue where string fields from eBPF events in columns output mode are not sanitized, potentially allowing maliciously crafted event payloads from observed containers to inject ANSI escape sequences into the terminal of operators. This can lead to various effects due to the lack of sanitization of control characters. The columns output mode is the default when running Inspektor Gadget interactively.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25996
GHSA-34R5-6J7W-235F

Affected Products

Inspektor-Gadget