GHSA-2mjq-54qg-7w6j

Suggest an improvement
Source
https://github.com/advisories/GHSA-2mjq-54qg-7w6j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2mjq-54qg-7w6j/GHSA-2mjq-54qg-7w6j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2mjq-54qg-7w6j
Aliases
Published
2026-03-21T00:31:43Z
Modified
2026-03-26T21:11:07Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
NFS CSI driver for Kubernetes is Vulnerable to Path Traversal through Volume Identifier Parameter
Details

A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During volume deletion or cleanup operations, the driver could operate on unintended directories outside the intended managed path within the NFS export. This may lead to deletion or modification of directories on the NFS server.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-24T16:11:26Z",
    "nvd_published_at":  "2026-03-20T23:16:48Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/kubernetes-csi/csi-driver-nfs

Package

Name
github.com/kubernetes-csi/csi-driver-nfs
View open source insights on deps.dev
Purl
pkg:golang/github.com/kubernetes-csi/csi-driver-nfs

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260210055231-316af2d86b91

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-2mjq-54qg-7w6j/GHSA-2mjq-54qg-7w6j.json"