3.8.13
Bugfix
- [security] Remember Me login tokens now actually expire after the configured timeout, closing a gap where a captured cookie stayed valid indefinitely instead of the default 7 days (GHSA-mj78-8gwc-vxjj). Thanks to chakrapani150 for the report.