PT-2026-103904 · Amazon Web Services · Aws-Efs-Csi-Driver
CVE-2026-103505
·
Published
2026-10-01
·
Updated
2026-10-02
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AWS EFS CSI Driver (aws-efs-csi-driver) versions 3.1.0 through 3.4.2
Description
Improper neutralization of argument delimiters in the volume handling component allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options. This is achieved by appending comma-separated values to the
mounttargetipmap volumeAttribute, which the mount process then parses as additional options.Recommendations
Upgrade to version 3.5.0 or later.
Restrict permissions for users who can create PersistentVolumes.
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws-Efs-Csi-Driver