CVE-2026-103505: Aws Aws-Efs-Csi-Driver

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. To remediate this issue, users should upgrade to version v3.5.0 or later.

Affected products

  • Aws Aws-Efs-Csi-Driver: from 3.1.0, up to and including 3.4.2

Published 2026-10-01. Last modified 2026-10-02.