CVE-2026-6437: Amazon Efs Csi Driver

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1

Affected products

  • Amazon Efs Csi Driver: before 3.0.1 (fixed in 3.0.1)

Published 2026-04-17. Last modified 2026-06-17.