To remediate this issue, users should upgrade to version v3.0.1
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mph4-q2vm-w2pw | Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 17 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon aws Efs Csi Driver |
|
| Vendors & Products |
Amazon
Amazon aws Efs Csi Driver |
Fri, 17 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1 | |
| Title | AWS EFS CSI Driver Mount Option Injection | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-04-17T19:57:02.728Z
Reserved: 2026-04-16T17:42:09.910Z
Link: CVE-2026-6437
Updated: 2026-04-17T19:56:52.356Z
Status : Received
Published: 2026-04-17T19:16:40.150
Modified: 2026-04-17T19:16:40.150
Link: CVE-2026-6437
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:35:10Z
Github GHSA