Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection.
To remediate this issue, users should upgrade to version v3.0.1
Metrics
Affected Vendors & Products
References
History
Fri, 17 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon aws Efs Csi Driver |
|
| Vendors & Products |
Amazon
Amazon aws Efs Csi Driver |
Fri, 17 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1 | |
| Title | AWS EFS CSI Driver Mount Option Injection | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published: 2026-04-17T18:41:36.075Z
Updated: 2026-04-17T19:57:02.728Z
Reserved: 2026-04-16T17:42:09.910Z
Link: CVE-2026-6437
Updated: 2026-04-17T19:56:52.356Z
Status : Received
Published: 2026-04-17T19:16:40.150
Modified: 2026-04-17T19:16:40.150
Link: CVE-2026-6437
No data.