GHSA-vwg3-w8w3-pc79 — getgrav/grav
Fix: getgrav/grav@8c9d1e7GHSA-vwg3-w8w3-pc79 is a CWE-178 vulnerability in getgrav/grav. A fix is available for getgrav/grav — see the affected versions and patch details below.
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
Exploitation and automatability from CISA’s SSVC triage for GHSA-vwg3-w8w3-pc79.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
getgrav/gravReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Summary
The default .htaccess shipped with Grav (and the reference webserver-configs/htaccess.txt) contains security rules that block direct HTTP access to sensitive file types (.yaml, .yml, .php, .json, .twig, etc.) under user/ and system/vendor/ directories. However, these rules lack the [NC] (No Case) flag, making them case-sensitive. On case-insensitive filesystems (Windows/NTFS, macOS/HFS+, or Linux with Docker volumes mounted from Windows/macOS), an attacker can bypass these rules by requesting files with uppercase extensions (e.g., .YAML, .PHP, .JSON).
Affected Versions
- Grav 2.0.1 (latest stable as of June 2026) — confirmed
- Grav 1.7.x — likely affected (same
.htaccessrules) - All versions shipping the current
webserver-configs/htaccess.txt
Affected Component
File: .htaccess (root of Grav installation)
Reference: webserver-configs/htaccess.txt
Affected Rules (lines 68, 70, 72)
# Line 68 — system/vendor file types
RewriteRule ^(system|vendor)/(.*)\.(txt|xml|md|html|htm|shtml|shtm|json|yaml|yml|php|php2|php3|php4|php5|phar|phtml|pl|py|cgi|twig|sh|bat)$ error [F]
# Line 70 — user file types
RewriteRule ^(user)/(.*)\.(txt|md|json|yaml|yml|php|php2|php3|php4|php5|phar|phtml|pl|py|cgi|twig|sh|bat)$ error [F]
# Line 72 — .md files globally
RewriteRule \.md$ error [F]
All three rules use [F] without [NC], making the extension match case-sensitive.
Steps to Reproduce
-
Install Grav on a system with a case-insensitive filesystem:
- Windows (native WAMP/XAMPP)
- macOS (default HFS+)
- Docker on Windows/macOS with volume mounts (e.g.,
./data:/var/www/html)
-
Create or use any plugin that stores sensitive data in its YAML config (e.g., API keys):
user/plugins/my-plugin/my-plugin.yaml -
Request the file with a case-varied extension:
GET /user/plugins/my-plugin/my-plugin.YAML HTTP/1.1 -
Expected: HTTP 403 Forbidden
-
Actual: HTTP 200 OK — full file contents returned, including any API keys or sensitive configuration
Impact
- Information disclosure: Plugin configuration files (
.yaml) containing API keys, credentials, or sensitive settings can be read by unauthenticated users - Source code exposure: PHP source files can be downloaded (instead of executed) when requested with
.PHPextension on some configurations - Configuration exposure:
user/config/system.yaml,user/config/site.yaml, and other system configuration files are accessible
Fix
Add the [NC] flag to the three affected rules:
RewriteRule ^(system|vendor)/(.*)\.(txt|xml|md|html|htm|shtml|shtm|json|yaml|yml|php|php2|php3|php4|php5|phar|phtml|pl|py|cgi|twig|sh|bat)$ error [F,NC]
RewriteRule ^(user)/(.*)\.(txt|md|json|yaml|yml|php|php2|php3|php4|php5|phar|phtml|pl|py|cgi|twig|sh|bat)$ error [F,NC]
RewriteRule \.md$ error [F,NC]
The [NC] flag makes the extension matching case-insensitive, covering .YAML, .Yaml, .PHP, .Json, etc.
Mitigating Factors
- On native Linux with ext4 filesystem (case-sensitive), the attack does not work because Apache cannot resolve the uppercase filename to the actual file
- Grav 2.0's Twig sandbox blocks access to
pluginsconfig subtree from page content, preventing SSTI-based config exfiltration - The
user/accounts/,user/config/, anduser/data/folders have separate rules (line 62, 66) that block ALL file types regardless of extension — these are not affected
Environment
- Grav: 2.0.1
- PHP: 8.3
- Apache: 2.4 with mod_rewrite
- OS: Docker (php:8.3-apache) with volume mounted from Windows 10 (NTFS)
- Tested: June 2026
Reporter
Sisnetic
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | getgrav/grav | all versions | 2.0.4composer require getgrav/grav:^2.0.4 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for getgrav/grav, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update getgrav/grav to 2.0.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-vwg3-w8w3-pc79 is resolved across your whole dependency graph.
Workarounds
Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them.
Frequently Asked Questions
Is GHSA-vwg3-w8w3-pc79 in your dependencies?
Find it across Packagist, including transitive dependencies.