Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thephpleague
Thephpleague flysystem |
|
| Vendors & Products |
Thephpleague
Thephpleague flysystem |
Tue, 29 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3. | |
| Title | Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter | |
| Weaknesses | CWE-150 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T16:02:04.360Z
Reserved: 2026-09-29T14:18:02.920Z
Link: CVE-2026-102601
No data.
Status : Received
Published: 2026-09-29T16:17:06.343
Modified: 2026-09-29T16:17:06.343
Link: CVE-2026-102601
No data.
OpenCVE Enrichment
Updated: 2026-09-29T17:30:17Z
-
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences