CVE-2026-42605: Php Flysystem Local Adapter Path Not Normalized

Path forwarded to a local filesystem adapter (getLocalPath / upload / download) without first passing through a PathNormalizer such as WhitespacePathNormalizer::normalizePath(). The local adapter ultimately delegates to PathPrefixer::prefixPath(), which is plain string concatenation, so '../' sequences in the supplied path will be resolved by the OS and allo

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-42605-php-flysystem-local-adapter-path-not-normalized --engine opengrep

Description

Path forwarded to a local filesystem adapter (getLocalPath / upload / download) without first passing through a PathNormalizer such as WhitespacePathNormalizer::normalizePath(). The local adapter ultimately delegates to PathPrefixer::prefixPath(), which is plain string concatenation, so '../' sequences in the supplied path will be resolved by the OS and allo