vulns.co
/
GKData.io MCP

Grav · 2 min read

Grav API: account-disable enforcement across session authenticators

GHSA-7qfj-82q8-frw6 describes inconsistent account-disable enforcement across authentication methods. Existing browser or remembered sessions could retain API authority because refreshed permissions did not also establish current account validity.

Open the reference Maintainer AdvisoryReviewed 2026-10-04

How to use this reference

Editorial lesson: authentication state is a revocable claim. Every authentication method should enforce the same account-lifecycle invariants, and failed account refresh must remove authority rather than preserve cached permission. The advisory describes requiring a freshly loaded, enabled account and failing closed on refresh errors. The official 1.0.36 release notes state that disabling or deleting an account immediately terminates its API sessions; this is maintainer-stated remediation, not an independently tested result.

Before reading

  • Basic understanding of authentication, account state and authorization

Context and limits

  • Requires an already authorized session belonging to the subsequently disabled account. The maintainer describes static-review findings, not a demonstrated production compromise. Retained access is bounded by prior permissions and session lifetime; no additional privilege is claimed.
  • The advisory lists affected versions through 1.0.35 and names 1.0.36 as patched, but its body still says no patch is available. That stale internal discrepancy remains in the advisory. The separately reviewed official 1.0.36 release and notes establish release availability and maintainer-stated session-revocation remediation, not independent verification of patch effectiveness.
  • Official GitHub release metadata records 1.0.36 as published on 2026-09-19 at 00:06:19 UTC, before the advisory's 2026-09-23 publication. This is the software release chronology, not the educational resource's edition date, the original report date or a verified deployment-fix date; dates.version_released remains null.
  • rhukster published the advisory and credits AlpetGexha as reporter; the 1.0.36 release notes also credit AlpetGexha for the account-session remediation. Original report date is unknown. Learning prerequisites and the invariant formulation are editorial.

Sources and provenance

  1. Disabled grav-plugin-api accounts retain access through existing sessions Grav · reviewed 2026-10-04
  2. Grav API 1.0.36 release notes Grav · reviewed 2026-10-04
  3. Official GitHub release metadata for Grav API 1.0.36 Grav / GitHub · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software