Security Advisory

CVE-2026-6437

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-17 18:41:36
Last updated 2026-04-17 19:57:02
Assigner AMZN
CVSS score 6.5
State PUBLISHED

Description

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, users should upgrade to version v3.0.1