Executive brief
The Grav Login Plugin, which handles user authentication for the Grav CMS, contains a flaw in its 'Remember Me' functionality. Due to a coding error, the system fails to expire long-term login tokens, allowing them to remain valid indefinitely regardless of security settings. If an attacker manages to steal a user's 'Remember Me' cookie, they could gain persistent, unauthorized access to the account even after the intended expiration period has passed.
Technical details
A vulnerability exists in the `TokenStorage::findTriplet()` method of the Grav Login Plugin due to an incorrect type comparison in PHP. The method attempts to validate the expiration of 'Remember Me' tokens by comparing a stored timestamp against the current time plus a timeout; however, the stored timestamp is nested within an array. In PHP, comparing an array to a scalar value (the timestamp) always evaluates in a way that bypasses the expiration check. Consequently, tokens never expire server-side unless manually cleared or overwritten. An attacker who captures a persistent login cookie can maintain access indefinitely, bypassing the `rememberme.timeout` security control. This issue is resolved in version 3.8.13.
Affected products
- getgrav Grav Login Plugin < 3.8.13
Timeline
- 2026-07-14: advisory: GitHub Security Advisory published by vendor
- 2026-07-29: disclosed: NVD publication date