Path Manipulation Vulnerability in Flysystem Library by The PHP League
CVE-2026-102601

3.5LOW

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102601?

The Flysystem library, utilized for file storage in PHP applications, has a vulnerability that allows malformed UTF-8 paths to evade detection when normalized. Specifically, the WhitespacePathNormalizer mishandles certain inputs, resulting in the potential for systems to store and list filenames containing control characters or ANSI escape sequences. This could lead to misrepresented file listings within terminal interfaces, especially for administrative users, allowing for the possibility of confusing or misleading output. The issue is addressed in version 3.35.3 of Flysystem.

Affected Version(s)

flysystem < 3.35.3

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.