CVE-2026-61452: Getgrav Grav
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour) regardless of logout, password change, new token issuance, or account disablement. An attacker who has stolen an access token retains full API access until the token naturally expires.
Affected products
- Getgrav Grav: before 2.0.4 (fixed in 2.0.4)
Published 2026-07-15. Last modified 2026-07-15.