Mmastodon TechnologyCybersecurity first seen 14 h ago, last 14 h ago, peak #2
Flysystem vulnerability lets malicious filenames hide terminal escape sequences
Original: CVE-2026-102601 affects Flysystem, The PHP League's PHP file storage library. Malformed UTF-8 in a path bypasses the con
A newly disclosed vulnerability, CVE-2026-102601, affects Flysystem, The PHP League's widely used PHP file storage library. Malformed UTF-8 in a file path bypasses the control-character check across all storage adapters, allowing stored filenames to hide terminal escape sequences that execute when files are listed. Versions 3.35.2 and earlier are affected, and developers are being urged to update.
Why now: Security researchers and PHP developers are sharing the advisory because Flysystem is a widely deployed library and the flaw affects all storage adapters.
FlysystemThe PHP LeagueCVE-2026-102601
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/377984