Sceawere
Vulnerability Detail
CVE-2026-102601UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Flysystem Path Normalization UTF-8 Bypass
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.5
- Creation Date
- 9h ago
- Vendor
- thephpleague
- Product
- flysystem
- Attack Type
- CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.5",
"pubDate": "2026-09-29T16:17:06.343Z",
"pubdate": "2026-09-29T16:17:06.343Z",
"executiveSummary": "Flysystem versions prior to 3.35.3 are vulnerable to a path normalization bypass flaw located within the WhitespacePathNormalizer component.\nThe vulnerability arises from improper handling of malformed UTF-8 sequences during the path validation process, specifically involving the preg_match function with the u modifier.\nBy supplying a path containing both malformed UTF-8 and ANSI escape sequences, an attacker can circumvent the CorruptedPathDetected::forPath() security check.\nThis allows the filesystem to store and subsequently retrieve file names containing control characters that were intended to be blocked by the library's normalization logic.\nThe primary risk implication is the potential for terminal-based spoofing or obfuscation when an administrator or automated system lists the contents of a directory.\nSuccessful exploitation allows attackers to disguise malicious files or inject terminal command sequences into logs and administrative interfaces, potentially misleading operators or triggering unintended behavior in terminal emulators.\nThe issue does not require specific authentication beyond the ability to write to the storage adapter, making it a concern for applications that accept user-controlled file names.",
"technicalDetails": "The vulnerability is rooted in the implementation of the WhitespacePathNormalizer::normalizePath() method within src/WhitespacePathNormalizer.php. The library relies on preg_match using the PCRE_UTF8 ('u') modifier to validate paths. In PHP, when the PCRE engine encounters malformed UTF-8 sequences, the preg_match function returns 'false' rather than '0' (no match) or '1' (match).\nThe logical error occurs because the validation logic treats both 'false' (error state) and '0' (no match) as falsy values. Consequently, the CorruptedPathDetected::forPath() check is bypassed entirely when a malformed UTF-8 sequence triggers a PCRE failure. This failure prevents the security logic from identifying potentially dangerous path characters, effectively disabling the normalization and filtering mechanisms for these specific inputs.\nThe attack flow proceeds as follows: First, an attacker crafts a malicious filename containing a malformed UTF-8 sequence coupled with ANSI escape codes (e.g., control sequences for terminal cursor movement or text formatting). Second, this string is passed to Filesystem::write(). Because the normalization process fails to recognize the malicious payload as 'corrupted' due to the false-negative evaluation, the filesystem accepts the file write operation and persists the raw ANSI sequence to the storage adapter.\nThird, when an administrator subsequently executes a command such as Filesystem::listContents() to view the directory, the library returns the stored, unsanitized file names. Finally, if these names are rendered in a terminal or a web-based administrative console that interprets ANSI sequences, the malicious codes are executed by the terminal emulator.\nThis behavior can lead to significant post-exploitation impacts, such as 'terminal spoofing,' where an attacker masks the presence of unauthorized files, redirects output, or modifies the display to hide logs or system information. The vulnerability affects all Filesystem adapters that utilize WhitespacePathNormalizer, and exploitation is possible provided the attacker has write access to the filesystem, regardless of network exposure or specific privilege levels, as it relies on the internal handling of character streams rather than external protocol abuse."
}