#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
Discover the best posts from developers and engineering teams, all in one place.
Join now
→
Learn more
TOPICS
Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage
1
·
Sentinelone
·
July 24, 2026, 1:38 a.m.
SentinelOne Insider
Container Security
CSI controller
kubernetes CSI driver
Kubernetes
Security
CVEs
Path Traversal
Summary
This blog post discusses how a misunderstanding of filepath.Join led to cross-tenant path traversal vulnerabilities in Kubernetes CSI drivers, highlighting potential security risks within Kubernetes storage systems.
Read full post on www.sentinelone.com →
MORE POSTS LIKE THIS
k8s: Kubernetes v1.35: A Better Way to Pass Service Account Tokens to CSI Drivers
Sujith Quintelier ·
Jan 8, 2026
Kubernetes
CSI Drivers
Why your RBAC linter misses privilege escalation chains (and how to fix it)
Red Hat ·
Jul 7, 2026
Kubernetes
rbac
Palana (Part 1): Why Grab built a secure platform for autonomous AI Agents
Grab ·
Jun 19, 2026
Security
artificial-intelligence
Edera gives Kubernetes the missing metrics for more efficient AI scheduling
Thestack ·
Jun 2, 2026
AI
Kubernetes
NGINX Ingress Controller 5.5: Security, Performance, and Easier Migration
Blog Nginx ·
May 29, 2026
Announcement
ingress
Unauthenticated Execution Threatens Kubernetes Clusters
Securityonline ·
May 27, 2026
Vulnerability Report
cloud-security
Discover more posts →
AUTHOR
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google