Vulnerability GHSA-9f46-5r25-5wfm
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
5 years ago
June 29, 2021 at 03:13 AM UTC
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
0.1.0 - 0.5.12 and 1.0.0 - 1.1.3 and 2.0.0 - 2.1.0
0.1.0 - 0.5.12 and 1.0.0 - 1.1.3 and 2.0.0 - 2.1.0
Summary
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
Details
Impact
The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely.
The conditions:
- A user is allowed to supply the path or filename of an uploaded file.
- The supplied path or filename is not checked against unicode chars.
- The supplied pathname checked against an extension deny-list, not an allow-list.
- The supplied path or filename contains a unicode whitespace char in the extension.
- The uploaded file is stored in a directory that allows PHP code to be executed.
Given these conditions are met a user can upload and execute arbitrary code on the system under attack.
Patches
The unicode whitespace removal has been replaced with a rejection (exception).
The library has been patched in:
- 1.x: https://github.com/thephpleague/flysystem/commit/f3ad69181b8afed2c9edf7be5a2918144ff4ea32
- 2.x: https://github.com/thephpleague/flysystem/commit/a3c694de9f7e844b76f9d1b61296ebf6e8d89d74
Workarounds
For 1.x users, upgrade to 1.1.4. For 2.x users, upgrade to 2.1.1.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Impacted packages
Timeline
Published
5 years ago
June 29, 2021 at 03:13 AM UTC
Fixed (1.1.4)
5 years ago
June 23, 2021 at 09:56 PM UTC
Fixed (2.1.1)
5 years ago
June 23, 2021 at 10:07 PM UTC
Last Modified
2 months ago
July 08, 2026 at 06:28 AM UTC