CVE-2026-24905 | inspektor-gadget Inspektor Gadget up to 0.48.0 build.go command injection (GHSA-79qw-g77v-2vfh / EUVD-2026-4954)
A vulnerability, which was classified as critical, has been found in inspektor-gadget Inspektor Gadget up to 0.48.0. Affected is an unknown function of the file inspektor-gadget/cmd/common/image/build.go. The manipulation leads to command injection.
This vulnerability is listed as CVE-2026-24905. The attack must be carried out locally. There is no available exploit.
It is advisable to upgrade the affected component.