Executive brief
The Login plugin for the Grav CMS contains a security flaw that allows an attacker to reset a user's two-factor authentication (2FA) settings. By tricking a logged-in user into clicking a malicious link, an attacker can force the system to generate a new security secret, making the user's existing authenticator app stop working. This results in a service disruption where the user must re-enroll their 2FA device to regain full access to their account.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'login.regenerate2FASecret' frontend task of the Grav Login plugin. The application fails to implement anti-CSRF nonces or Origin/Referer checks for this specific task. Because Grav dispatches tasks via GET parameters and uses 'SameSite=Lax' for session cookies by default, an attacker can trigger the secret regeneration via a top-level GET navigation (e.g., a malicious link). This overwrites the 'twofa_secret' in the user's account file, desynchronizing their authenticator app from the server. The vulnerability is patched in version 3.8.11; sites using 'session.samesite: Strict' are not affected.
Affected products
- getgrav grav-plugin-login < 3.8.11
Timeline
- 2026-06-29: advisory: GitHub Security Advisory published
- 2026-07-17: disclosed: NVD publication date