Intel

AIKIDO-2026-10164

sigs.k8s.io/azurefile-csi-driver is vulnerable to Dependency on Vulnerable Third-Party Component

Dependency on Vulnerable Third-Party Component Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

75

High Risk

This Affects:

GOsigs.k8s.io/azurefile-csi-driver
0.0.1 - 1.34.3
Fixed in 1.35.0

TL;DR

Affected versions of this package are vulnerable to multiple CVEs (CVE-2025-52881, CVE-2025-47914, CVE-2025-58181, CVE-2025-13281, CVE-2025-47912, CVE-2025-61727) that may not be detected by standard software composition analysis (SCA) scanners, potentially leaving known vulnerabilities unnoticed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

sigs.k8s.io/azurefile-csi-driver is vulnerable to Dependency on Vulnerable Third-Party Component in versions 0.0.1 - 1.34.3.

How to fix this

Upgrade the sigs.k8s.io/azurefile-csi-driver library to a patch version.

Background Info