To remediate this issue, users should upgrade to version v3.0.1
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mph4-q2vm-w2pw | Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields |
Mon, 20 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 17 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon aws Efs Csi Driver |
|
| Vendors & Products |
Amazon
Amazon aws Efs Csi Driver |
Fri, 17 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1 | |
| Title | AWS EFS CSI Driver Mount Option Injection | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-04-17T19:57:02.728Z
Reserved: 2026-04-16T17:42:09.910Z
Link: CVE-2026-6437
Updated: 2026-04-17T19:56:52.356Z
Status : Awaiting Analysis
Published: 2026-04-17T19:16:40.150
Modified: 2026-04-20T19:05:30.750
Link: CVE-2026-6437
OpenCVE Enrichment
Updated: 2026-04-18T17:15:05Z
Github GHSA