High severity7.5NVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
CVE-2026-62230
CVE-2026-62230
Description
Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching case-sensitive. On case-insensitive filesystems (Windows/NTFS, macOS/HFS+, or Docker volume mounts), an unauthenticated attacker can request these files with uppercase or mixed-case extensions (e.g., .YAML, .PHP) to bypass the restrictions and read sensitive configuration files that may contain API keys and credentials.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.