MEDIUM4.4Packagist
GHSA-3xjv-pmf2-gf2q· CVE-2026-42549Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root
Modified: 5/14/2026
package
pkg:packagist/flightphp/core
Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root
Modified: 5/14/2026
Flight has reflected XSS through an unvalidated JSONP callback in Flight::jsonp()
Modified: 5/14/2026
Flight vulnerable to sensitive information disclosure via default error handler
Modified: 5/14/2026
Flight: HTTP method override enabled by default, facilitating CSRF escalation and middleware bypass
Modified: 5/14/2026
Flight vulnerable to SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete
Modified: 5/14/2026