{"id":"CVE-2026-102601","title":"Flysystem is an open source file storage library for PHP","summary":"Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both f…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-150"],"vendor":"thephpleague","product":"flysystem","affected":["flysystem < 3.35.3"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:06.343","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102601","references":[{"url":"https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77","label":"security-advisories@github.com"},{"url":"https://github.com/thephpleague/flysystem/releases/tag/3.35.3","label":"security-advisories@github.com"},{"url":"https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr","label":"security-advisories@github.com"},{"url":"https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-29T16:01:15.275868Z"},"ingestedAt":"2026-09-29T16:39:33.263Z","slug":"CVE-2026-102601","body":"## Overview\n\nFlysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":31,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}