Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-61452

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour) regardless of logout, password change, new token issuance, or account disablement. An attacker who has stolen an access token retains full API access until the token naturally expires.

EPSS

Процентиль: 9%
0.00194
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5.3
github
около 1 месяца назад

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour) regardless of logout, password change, new token issuance, or account disablement. An attacker who has stolen an access token retains full API access until the token naturally expires.

EPSS

Процентиль: 9%
0.00194
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-613