{"id":"CVE-2026-103505","title":"AWS EFS CSI Driver Mount Option Injection via mounttargetipmap","summary":"Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject …","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cvssSource":"cna","cwe":["CWE-88"],"vendor":"AWS","product":"aws-efs-csi-driver","affected":["aws-efs-csi-driver >= 3.1.0 <= 3.4.2"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:36:04.355Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-103505","references":[{"url":"https://github.com/kubernetes-sigs/aws-efs-csi-driver/releases/tag/v3.5.0"},{"url":"https://aws.amazon.com/security/security-bulletins/2026-120-aws/"}],"tags":["cve.org"],"ingestedAt":"2026-10-01T15:48:17.832Z","slug":"CVE-2026-103505","body":"## Overview\n\nImproper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute.\n\n\n\nTo remediate this issue, users should upgrade to version v3.5.0 or later.\n\n## Affected\n\n- `aws-efs-csi-driver >= 3.1.0 <= 3.4.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}