{"ok":true,"trend":{"id":377984,"platform":"mastodon","region":"global","key":"cve-2026-102601 affects flysystem, the php league's php file storage library. malformed utf-8 in a path bypasses the con","title":"CVE-2026-102601 affects Flysystem, The PHP League's PHP file storage library. Malformed UTF-8 in a path bypasses the con","url":"https://infosec.exchange/@suriq/117355225420960486","first_seen":"2026-09-29T16:21:49.144060Z","last_seen":"2026-09-29T16:21:49.144060Z","last_rank":7,"peak_rank":2,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.93359375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A newly disclosed vulnerability, CVE-2026-102601, affects Flysystem, The PHP League's widely used PHP file storage library. Malformed UTF-8 in a file path bypasses the control-character check across all storage adapters, allowing stored filenames to hide terminal escape sequences that execute when files are listed. Versions 3.35.2 and earlier are affected, and developers are being urged to update.","why":"Security researchers and PHP developers are sharing the advisory because Flysystem is a widely deployed library and the flaw affects all storage adapters.","tone":"neutral","entities":["Flysystem","The PHP League","CVE-2026-102601"],"summarized_at":"2026-09-29T16:22:37.740693Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1233},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Flysystem vulnerability lets malicious filenames hide terminal escape sequences","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-29T16:21:49.144060Z","rank":2,"volume":1},{"captured_at":"2026-09-29T16:21:49.144060Z","rank":7,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@suriq/117355225420960486","author":"suriq@infosec.exchange","title":null,"snippet":"CVE-2026-102601 affects Flysystem, The PHP League's PHP file storage library. Malformed UTF-8 in a path bypasses the control-character check across all storage adapters. Stored filenames can hide terminal escape sequences shown when listing files. Affected: versions 3.35.2 and…","posted_at":"2026-09-29T16:17:10Z","likes":1}],"elsewhere":[],"window":"7d"}}