PKSA-w9tt-7782-78jx Security Advisory
-
[LOW] Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter
PKSA-w9tt-7782-78jx CVE-2026-102601 GHSA-cxf4-7mrp-vvpr
Affected package: league/flysystem
Affected version: <=3.35.2
Reported by:
GitHub