MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 17 h ago, last 17 h ago, peak #2

Flysystem vulnerability lets malicious filenames hide terminal escape sequences

Original: CVE-2026-102601 affects Flysystem, The PHP League's PHP file storage library. Malformed UTF-8 in a path bypasses the con

A newly disclosed vulnerability, CVE-2026-102601, affects Flysystem, The PHP League's widely used PHP file storage library. Malformed UTF-8 in a file path bypasses the control-character check across all storage adapters, allowing stored filenames to hide terminal escape sequences that execute when files are listed. Versions 3.35.2 and earlier are affected, and developers are being urged to update.

Why now: Security researchers and PHP developers are sharing the advisory because Flysystem is a widely deployed library and the flaw affects all storage adapters.

FlysystemThe PHP LeagueCVE-2026-102601

Open on mastodon →

Rank over time, top of the chart is #1. 2 snapshots from 17 h ago to 17 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/377984