THREAT OPS › Threat News › [GHSA] GHSA-vwg3-w8w3-pc79 (high) — Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
[GHSA] GHSA-vwg3-w8w3-pc79 (high) — Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
GHSA-vwg3-w8w3-pc79 Severity: high CVE: CVE-2026-62673
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
## Summary
The default `.htaccess` shipped with Grav (and the reference `webserver-configs/htaccess.txt`) contains security rules that block direct HTTP access to sensitive file types (`.yaml`, `.yml`, `.php`, `.json`, `.twig`, etc.) under `user/`
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-62673cve
Original source: https://github.com/advisories/GHSA-vwg3-w8w3-pc79