MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 21 h ago, last 21 h ago, peak #2

Flysystem vulnerability lets malicious filenames hide terminal escape sequences

Original: CVE-2026-102601 affects Flysystem, The PHP League's PHP file storage library. Malformed UTF-8 in a path bypasses the con

A newly disclosed vulnerability, CVE-2026-102601, affects Flysystem, The PHP League's widely used PHP file storage library. Malformed UTF-8 in a file path bypasses the control-character check across all storage adapters, allowing stored filenames to hide terminal escape sequences that execute when files are listed. Versions 3.35.2 and earlier are affected, and developers are being urged to update.

Why now: Security researchers and PHP developers are sharing the advisory because Flysystem is a widely deployed library and the flaw affects all storage adapters.

FlysystemThe PHP LeagueCVE-2026-102601

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/377984