{"id":"CVE-2026-103505","summary":"AWS EFS CSI Driver Mount Option Injection via mounttargetipmap","details":"Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma-separated values in the mounttargetipmap volumeAttribute.\n\n\n\nTo remediate this issue, users should upgrade to version v3.5.0 or later.","aliases":["GHSA-pv26-6q9q-5773"],"modified":"2026-10-04T02:30:55.807998045Z","published":"2026-10-01T15:36:04.355Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103505.json","cna_assigner":"AMZN","cwe_ids":["CWE-88"]},"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-120-aws/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103505.json"},{"type":"ADVISORY","url":"https://github.com/kubernetes-sigs/aws-efs-csi-driver/security/advisories/GHSA-pv26-6q9q-5773"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103505"},{"type":"FIX","url":"https://github.com/kubernetes-sigs/aws-efs-csi-driver/releases/tag/v3.5.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kubernetes-sigs/aws-efs-csi-driver","events":[{"introduced":"1cf7fa72c5db2310abecf7523f442df23e7e37f3"},{"fixed":"c5f0010c9b857316fe3891a2a4b1129f547791be"},{"fixed":"978c0b0be261904014ffd68af35a7421bbf439a4"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"v3.1.0"},{"fixed":"v3.4.2"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103505.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:N/SA:N"}]}