Path Manipulation Vulnerability in Flysystem Library by The PHP League
CVE-2026-102601
3.5LOW
What is CVE-2026-102601?
The Flysystem library, utilized for file storage in PHP applications, has a vulnerability that allows malformed UTF-8 paths to evade detection when normalized. Specifically, the WhitespacePathNormalizer mishandles certain inputs, resulting in the potential for systems to store and list filenames containing control characters or ANSI escape sequences. This could lead to misrepresented file listings within terminal interfaces, especially for administrative users, allowing for the possibility of confusing or misleading output. The issue is addressed in version 3.35.3 of Flysystem.
Affected Version(s)
flysystem < 3.35.3
