Amazon EFS CSI Driver Vulnerability Lets Attackers Inject Mount Options
Amazon EFS CSI Driver versions 3.1.0 through 3.4.2 have a mount option injection flaw (CVE-2026-103505). Users with PersistentVolume creation privileges can exploit the mounttargetipmap attribute to inject malicious mount options. If you're running affected versions, update immediately—this requires action.
source: [aws/security-bulletin]