Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute.
To remediate this issue, users should upgrade to version v3.5.0 or later.
To remediate this issue, users should upgrade to version v3.5.0 or later.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aws
Aws aws-efs-csi-driver |
|
| Vendors & Products |
Aws
Aws aws-efs-csi-driver |
Thu, 01 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. To remediate this issue, users should upgrade to version v3.5.0 or later. | |
| Title | AWS EFS CSI Driver Mount Option Injection via mounttargetipmap | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-10-01T16:02:04.918Z
Reserved: 2026-09-30T17:35:44.736Z
Link: CVE-2026-103505
No data.
Status : Received
Published: 2026-10-01T16:17:36.627
Modified: 2026-10-01T16:17:36.627
Link: CVE-2026-103505
No data.
OpenCVE Enrichment
Updated: 2026-10-01T16:30:10Z
Weaknesses