← Back to feed
Securitykubernetes_cveAlphaLab AI score 26/100

Kubernetes CSI Driver for NFS Exposes Critical Path Traversal Flaw

A vulnerability in the Kubernetes CSI Driver for NFS, identified as CVE-2026-3864, allows path traversal via the subDir parameter, potentially leading to the deletion of unintended directories on the NFS server. This issue arises when the driver incorrectly handles resource paths, enabling unauthorized access to critical files and directories. Administrators using the CSI Driver for NFS should apply updates or configure access controls to mitigate the risk. The vulnerability highlights the importance of secure path handling in storage drivers, particularly in multi-tenant environments where unintended directory deletions could disrupt operations.

Original source← Back to feed