CVE-2026-102601
3.5 LOWpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Weaknesses
CWE-150
Public exploit & PoC references
- https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77
- https://github.com/thephpleague/flysystem/releases/tag/3.35.3
- https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
- https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
All references
- https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77
- https://github.com/thephpleague/flysystem/releases/tag/3.35.3
- https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
- https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
Related by shared AI tags and CWE weakness class. Browse the full archive.