Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2… (CVE-2026-103505)
AWS EFS CSI Driver versions 3.1.0 through 3.4.2 contain a vulnerability where improper neutralization of argument delimiters in the volume handling component allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options. This can lead to high confidentiality and integrity impacts. The issue is fixed in version 3.5.0 and later.
AI Analysis
Technical Summary
CVE-2026-103505 describes a vulnerability in AWS EFS CSI Driver versions 3.1.0 through 3.4.2 where improper neutralization of argument delimiters in the volume handling component allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. This could lead to unauthorized modification of mount options, impacting confidentiality and integrity of the system. The vulnerability is tracked under CWE-88 (Improper Neutralization of Argument Delimiters).
Potential Impact
An attacker with PersistentVolume creation permissions can inject arbitrary mount options, potentially compromising the confidentiality and integrity of the system. The CVSS v3.1 base score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, high privileges required, no user interaction, and high confidentiality and integrity impact.
Mitigation Recommendations
Users should upgrade to AWS EFS CSI Driver version 3.5.0 or later to remediate this vulnerability. No other mitigation or temporary fix is indicated.
Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2… (CVE-2026-103505)
Description
AWS EFS CSI Driver versions 3.1.0 through 3.4.2 contain a vulnerability where improper neutralization of argument delimiters in the volume handling component allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options. This can lead to high confidentiality and integrity impacts. The issue is fixed in version 3.5.0 and later.
CVSS v3.1
Score 6.5medium
Affected software
pkg:github/kubernetes-sigs/aws-efs-csi-driverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-103505 describes a vulnerability in AWS EFS CSI Driver versions 3.1.0 through 3.4.2 where improper neutralization of argument delimiters in the volume handling component allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute. This could lead to unauthorized modification of mount options, impacting confidentiality and integrity of the system. The vulnerability is tracked under CWE-88 (Improper Neutralization of Argument Delimiters).
Potential Impact
An attacker with PersistentVolume creation permissions can inject arbitrary mount options, potentially compromising the confidentiality and integrity of the system. The CVSS v3.1 base score is 6.5 (medium severity), reflecting network attack vector, low attack complexity, high privileges required, no user interaction, and high confidentiality and integrity impact.
Mitigation Recommendations
Users should upgrade to AWS EFS CSI Driver version 3.5.0 or later to remediate this vulnerability. No other mitigation or temporary fix is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9w9f-p9qm-rcm4
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-103505"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abeb3e7a43b0b3b89ed1e82
Added to database: 10/01/2026, 19:26:31 UTC
Last enriched: 10/01/2026, 19:30:20 UTC
Last updated: 10/02/2026, 04:45:56 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.