Flysystem · Flysystem · CVE-2026-102601
**Name of the Vulnerable Software and Affected Versions**
Flysystem versions prior to 3.35.3
**Description**
In the `WhitespacePathNormalizer` class within `src/WhitespacePathNormalizer.php`, the `normalizePath()` function uses `preg match()` with the `u` modifier to detect control characters. When a path contains malformed UTF-8 characters, `preg match()` returns `false` instead of `0`. Because the code uses a truthy check, it fails to distinguish between a non-match and an engine error, allowing paths with both malformed UTF-8 and control characters to bypass the `CorruptedPathDetected::forPath()` exception.
This allows `Filesystem::write()` to store files with malicious names. Subsequently, `Filesystem::listContents()` can return raw ANSI escape sequences, which may lead to hidden or spoofed terminal file listings when viewed by an administrator.
**Recommendations**
Update Flysystem to version 3.35.3 or later.
As a temporary mitigation, restrict the use of the `normalizePath()` function or validate that input paths contain only valid UTF-8 characters before they are processed by the library.