league/flysystem Security Advisories for 0.1.16 (2)
-
[LOW] Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter
PKSA-w9tt-7782-78jx CVE-2026-102601 GHSA-cxf4-7mrp-vvpr
Affected version: <=3.35.2
Reported by:
GitHub -
[CRITICAL] TOCTOU Race Condition enabling remote code execution
PKSA-pwh8-d4fr-nywn CVE-2021-32708 GHSA-9f46-5r25-5wfm
Affected version: <1.1.4|>=2.0.0,<2.1.1
Reported by:
GitHub, FriendsOfPHP/security-advisories