PT-2026-103904 · Amazon Web Services · Aws-Efs-Csi-Driver

CVE-2026-103505

·

Published

2026-10-01

·

Updated

2026-10-02

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AWS EFS CSI Driver (aws-efs-csi-driver) versions 3.1.0 through 3.4.2
Description Improper neutralization of argument delimiters in the volume handling component allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options. This is achieved by appending comma-separated values to the mounttargetipmap volumeAttribute, which the mount process then parses as additional options.
Recommendations Upgrade to version 3.5.0 or later. Restrict permissions for users who can create PersistentVolumes.

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103505

Affected Products

Aws-Efs-Csi-Driver