PT-2026-60640 · Grav · Grav
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.4
Description
An unauthenticated attacker can bypass restrictions on sensitive file types by requesting files with uppercase or mixed-case extensions (e.g., .YAML, .PHP). This occurs because the default .htaccess file and the
webserver-configs/htaccess.txt reference lack the [NC] (No Case) flag, making extension matching case-sensitive. On case-insensitive filesystems, such as Windows/NTFS, macOS/HFS+, or Docker volume mounts, this allows the unauthorized reading of sensitive configuration files that may contain credentials and API keys.Recommendations
Update Grav to version 2.0.4 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav