Where
-Infinity
0
Severity
6.5
EPSS
0.10%
Path Traversal
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was insufficiently validated. Attackers with the ability to create PersistentVolumes referencing the NFS CSI driver could craft volume identifiers containing path traversal sequences (../). During volume deletion or cleanup operations, the driver could operate on unintended directories outside the intended managed path within the NFS export. This may lead to deletion or modification of directories on the NFS server.

Remedy

Upgrade the CSI Driver for NFS to version 4.13.1 or later. As mitigations, restrict PersistentVolume creation privileges to trusted administrators and review NFS exports to ensure only intended directories are writable by the driver.
First published (updated )

Hello Kubernetes Community,

A vulnerability was identified in the Kubernetes CSI Driver for NFS where insufficient validation of the subDir parameter in volume identifiers could allow path traversal. A malicious user with the ability to create a PersistentVolume referencing the NFS CSI driver could craft a volumeHandle containing traversal sequences (for example ../). When the driver performs cleanup operations during volume deletion, these sequences may cause the driver to operate on unintended directories on the NFS server.

An attacker exploiting this flaw could cause deletion or modification of directories outside the intended managed subdirectory within the NFS export.

This issue has been rated Medium (6.5) with CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H <https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H> and assigned CVE-2026-3864.

Am I vulnerable?

You may be vulnerable if:

-

You run the CSI Driver for NFS (nfs.csi.k8s.io) -

Your cluster allows users to create PersistentVolumes referencing the NFS CSI driver -

Your CSI driver version does not validate traversal sequences in the subDir field

Affected Versions

-

All versions of the CSI Driver for NFS prior to the v4.13.1 release containing the fix for traversal validation are affected.

How do I mitigate this vulnerability?

This issue can be mitigated by:

-

Upgrading the CSI Driver for NFS to a patched version -

Restricting PersistentVolume creation privileges to trusted administrators -

Reviewing NFS exports to ensure only intended directories are writable by the driver

As a best practice, untrusted users should not be granted permission to create arbitrary PersistentVolumes referencing external storage drivers.

Fixed Versions

-

CSI Driver for NFS versions >= v4.13.1

Detection

To determine if your cluster may be affected:

-

Inspect PersistentVolumes using the NFS CSI driver and review the volumeHandle field. -

Look for traversal sequences such as: ../ -

Review CSI controller logs for unexpected directory operations. e.g. “Removing subPath: /tmp/mount-uuid/legitimate/../../../exports/subdir”

If you find evidence that this vulnerability has been exploited, please contact security () kubernetes io

Thank You,

Rita Zhang on behalf of the Kubernetes Security Response Committee

Additional Details

See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/137797

Acknowledgements

This vulnerability was reported by @Shaul Ben Hai, Senior Staff Security Researcher from SentinelOne.

The issue was fixed by the CSI Driver for NFS maintainers and the Kubernetes Security Response Committee.

Andy Zhang @andyzhangx

Rita Zhang @ritazh

Thank You,

Rita Zhang on behalf of the Kubernetes Security Response Committee

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203