MikeTrendsTrends right now

search

CVE-2026-102601

Trends

  1. 1
    Flysystem vulnerability lets malicious filenames hide terminal escape sequences▼CVE-2026-102601 affects Flysystem, The PHP League's PHP file storage library. Malformed UTF-8 in a path bypasses the conMmastodonTechnologyCybersecurity11 d ago

    A newly disclosed vulnerability, CVE-2026-102601, affects Flysystem, The PHP League's widely used PHP file storage library. Malformed UTF-8 in a file path bypasses the control-character check across all storage adapters, allowing stored filenames to hide terminal escape sequences that execute when files are listed. Versions 3.35.2 and earlier are affected, and developers are being urged to update.