Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/kubernetes-sigs/aws-efs-csi-driver
  4. ›
  5. CVE-2026-6437

CVE-2026-6437: Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields

April 18, 2026

The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount command, allowing injection of arbitrary mount options.

References

  • aws.amazon.com/security/security-bulletins/2026-016-aws
  • github.com/advisories/GHSA-mph4-q2vm-w2pw
  • github.com/kubernetes-sigs/aws-efs-csi-driver
  • github.com/kubernetes-sigs/aws-efs-csi-driver/commit/51806c22c5754bfbdeca6910f15571a07921b784
  • github.com/kubernetes-sigs/aws-efs-csi-driver/releases/tag/v3.0.1
  • github.com/kubernetes-sigs/aws-efs-csi-driver/security/advisories/GHSA-mph4-q2vm-w2pw
  • nvd.nist.gov/vuln/detail/CVE-2026-6437

Code Behaviors & Features

Detect and mitigate CVE-2026-6437 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.7.8-0.20260416142831-51806c22c575

Fixed versions

  • 1.7.8-0.20260416142831-51806c22c575

Solution

Upgrade to version 1.7.8-0.20260416142831-51806c22c575 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Source file

go/github.com/kubernetes-sigs/aws-efs-csi-driver/CVE-2026-6437.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:19:37 +0000.