To remediate this issue, users should upgrade to version v3.5.0 or later.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aws
Aws aws-efs-csi-driver |
|
| Vendors & Products |
Aws
Aws aws-efs-csi-driver |
Thu, 01 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. To remediate this issue, users should upgrade to version v3.5.0 or later. | |
| Title | AWS EFS CSI Driver Mount Option Injection via mounttargetipmap | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-10-01T16:02:04.918Z
Reserved: 2026-09-30T17:35:44.736Z
Link: CVE-2026-103505
No data.
Status : Received
Published: 2026-10-01T16:17:36.627
Modified: 2026-10-01T17:17:18.667
Link: CVE-2026-103505
No data.
OpenCVE Enrichment
Updated: 2026-10-01T16:30:10Z