logo

Kubernetes CSI Driver for NFS Vulnerability Lets Attackers Delete or Modify NFS Server Directories

ID: 071999dc-be87-51fc-a322-9311cec35796

STIX ID: report--071999dc-be87-51fc-a322-9311cec35796

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-03-17

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A path traversal vulnerability in the Kubernetes CSI Driver for NFS (nfs.csi.k8s.io) allows attackers who can create PersistentVolumes to include "../" sequences in the subDir/volumeHandle, which may cause the CSI controller to modify or delete directories outside the intended NFS export; all versions prior to v4.13.1 are affected and the recommended remediation is to upgrade to v4.13.1 or later and limit PV creation to trusted users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.