PT-2026-7900 · Unknown · Inspektor-Gadget
Ndaprela
+1
·
Published
2026-02-12
·
Updated
2026-04-28
·
CVE-2026-25996
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Inspektor Gadget (affected versions not specified)
Description
Inspektor Gadget has an issue where string fields from eBPF events in columns output mode are not sanitized, potentially allowing maliciously crafted event payloads from observed containers to inject ANSI escape sequences into the terminal of operators. This can lead to various effects due to the lack of sanitization of control characters. The columns output mode is the default when running Inspektor Gadget interactively.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inspektor-Gadget