CVE-2026-6437: Amazon Efs Csi Driver
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1
Affected products
- Amazon Efs Csi Driver: before 3.0.1 (fixed in 3.0.1)
Published 2026-04-17. Last modified 2026-06-17.