Vulnerability GHSA-9f46-5r25-5wfm

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
5 years ago
June 29, 2021 at 03:13 AM UTC
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
0.1.0 - 0.5.12 and 1.0.0 - 1.1.3 and 2.0.0 - 2.1.0
0.1.0 - 0.5.12 and 1.0.0 - 1.1.3 and 2.0.0 - 2.1.0

Summary

Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem

Details

Impact

The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely.

The conditions:

  • A user is allowed to supply the path or filename of an uploaded file.
  • The supplied path or filename is not checked against unicode chars.
  • The supplied pathname checked against an extension deny-list, not an allow-list.
  • The supplied path or filename contains a unicode whitespace char in the extension.
  • The uploaded file is stored in a directory that allows PHP code to be executed.

Given these conditions are met a user can upload and execute arbitrary code on the system under attack.

Patches

The unicode whitespace removal has been replaced with a rejection (exception).

The library has been patched in:

Workarounds

For 1.x users, upgrade to 1.1.4. For 2.x users, upgrade to 2.1.1.

Impacted packages

Timeline

Published
5 years ago
June 29, 2021 at 03:13 AM UTC
Fixed (1.1.4)
5 years ago
June 23, 2021 at 09:56 PM UTC
Fixed (2.1.1)
5 years ago
June 23, 2021 at 10:07 PM UTC
Last Modified
2 months ago
July 08, 2026 at 06:28 AM UTC