
CVE-2026-42549 Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recursive: true) on a path built from the user-supp… https://www.cve.org/CVERecord?id=CVE-2026-42549
Post summary
CVE-2026-42549 exposes Flight PHP’s CLI make:controller command to create directories from unsanitized user input, allowing potential arbitrary file creation; the issue is fixed in version 3.18.1.
