CVE-2026-103505: Aws Aws-Efs-Csi-Driver
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. To remediate this issue, users should upgrade to version v3.5.0 or later.
Affected products
- Aws Aws-Efs-Csi-Driver: from 3.1.0, up to and including 3.4.2
Published 2026-10-01. Last modified 2026-10-02.