---
id: CVE-2026-102601
title: Flysystem is an open source file storage library for PHP
summary: >-
  Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the
  default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by
  Filesystem across adapters calls preg_match with the u modifier and treats
  both f…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-150
vendor: thephpleague
product: flysystem
affected:
  - flysystem < 3.35.3
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T16:17:06.343'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102601'
references:
  - url: >-
      https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77
    label: security-advisories@github.com
  - url: 'https://github.com/thephpleague/flysystem/releases/tag/3.35.3'
    label: security-advisories@github.com
  - url: >-
      https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
    label: security-advisories@github.com
  - url: >-
      https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-29T16:01:15.275868Z'
ingestedAt: '2026-09-29T16:39:33.263Z'
---

## Overview

Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
