CVE-2026-102601: CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences in thephpleague flysystem
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3.
AI Analysis
Technical Summary
Thephpleague flysystem prior to version 3.35.3 uses a default WhitespacePathNormalizer that calls preg_match with the 'u' modifier and treats both false and 0 as falsy. When a path contains malformed UTF-8 sequences, PCRE returns false, causing the normalization function to bypass detection of corrupted paths containing control characters. Consequently, Filesystem::write() can store file names with such characters, and Filesystem::listContents() can return raw ANSI escape sequences. This behavior enables hidden or spoofed terminal file listings when administrators display directory contents. The vulnerability is addressed by fixing the normalization logic in version 3.35.3.
Potential Impact
This vulnerability allows an attacker to create files with names containing raw ANSI escape sequences that can be hidden or spoofed in terminal file listings. While it does not directly compromise confidentiality or availability, it can mislead administrators by presenting deceptive file listings, potentially complicating system management or forensic analysis. The CVSS score is 3.5 (low severity), indicating limited impact primarily on integrity of displayed file names.
Mitigation Recommendations
Upgrade thephpleague flysystem to version 3.35.3 or later, where the issue in WhitespacePathNormalizer is fixed. No other mitigations are indicated. Patch status is confirmed fixed in 3.35.3.
CVE-2026-102601: CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences in thephpleague flysystem
Description
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3.
CVSS v3.1
Score 3.5low
Affected software
thephpleague
flysystem
pkg:composer/thephpleague/flysystemRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Thephpleague flysystem prior to version 3.35.3 uses a default WhitespacePathNormalizer that calls preg_match with the 'u' modifier and treats both false and 0 as falsy. When a path contains malformed UTF-8 sequences, PCRE returns false, causing the normalization function to bypass detection of corrupted paths containing control characters. Consequently, Filesystem::write() can store file names with such characters, and Filesystem::listContents() can return raw ANSI escape sequences. This behavior enables hidden or spoofed terminal file listings when administrators display directory contents. The vulnerability is addressed by fixing the normalization logic in version 3.35.3.
Potential Impact
This vulnerability allows an attacker to create files with names containing raw ANSI escape sequences that can be hidden or spoofed in terminal file listings. While it does not directly compromise confidentiality or availability, it can mislead administrators by presenting deceptive file listings, potentially complicating system management or forensic analysis. The CVSS score is 3.5 (low severity), indicating limited impact primarily on integrity of displayed file names.
Mitigation Recommendations
Upgrade thephpleague flysystem to version 3.35.3 or later, where the issue in WhitespacePathNormalizer is fixed. No other mitigations are indicated. Patch status is confirmed fixed in 3.35.3.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-29T14:18:02.920Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abbddc9f7a7c5410696f02e
Added to database: 09/29/2026, 15:48:25 UTC
Last enriched: 09/29/2026, 16:02:44 UTC
Last updated: 09/29/2026, 17:09:08 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.