appsec.fyi

CSRF — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

CSRF: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 78 of 78 curated resources. Browse all 78 CSRF resources →

Problem Framing: The Persistent Threat of Cross-Site Request Forgery

Cross-Site Request Forgery (CSRF) remains a potent and persistent threat to web applications, despite decades of research and remediation efforts. At its core, CSRF exploits the inherent trust web applications place in a user's browser. When a user is authenticated to a site, their browser automatically includes session credentials (typically cookies) with subsequent requests. An attacker leverages this behavior by tricking the user's browser into sending a forged, state-changing request to the trusted application, making it appear as if the legitimate user initiated the action [1][2][3][4][5].

The impact of a successful CSRF attack can range from minor inconveniences, like changing user preferences, to critical security breaches, such as unauthorized financial transactions, account takeovers, or even full system compromise if an administrator's account is targeted [6][7][8][9][10]. The fundamental vulnerability lies in applications that perform state-changing operations based solely on session credentials, without adequately verifying user intent or the request's origin [11][12][13].

While modern browser security features like the SameSite cookie attribute have significantly reduced the attack surface, they haven't eliminated CSRF. Sophisticated techniques and subtle misconfigurations can still allow attackers to bypass these defenses. Understanding the mechanics of CSRF, its evolution, and the nuances of its exploitation is crucial for any application security professional.

Core Mechanics: How CSRF Works

A CSRF attack hinges on several key principles:

The attack typically involves the attacker crafting a malicious HTML document, often hosted on a separate domain. This document contains code that triggers an HTTP request to the vulnerable application. When the victim, who is already authenticated to the target application, visits the attacker's page, their browser automatically sends the forged request along with their session cookies. The server, receiving a request with valid credentials, processes the action as if the user intended it [8][1][2][3][4][5].

This can be achieved through various means:

Even actions like logging out can be vulnerable to CSRF, which can be chained with other attacks, such as phishing, to trick users into re-authenticating on a spoofed page [19].

Notable Techniques and Vulnerability Classes

The landscape of CSRF vulnerabilities is diverse, with techniques evolving to bypass common defenses.

Bypassing Referer-Based Protection

Some applications rely on the Referer header to validate the origin of requests. However, this header is not always reliably sent by browsers, and in certain specific scenarios, it can be manipulated to satisfy checks even on cross-origin requests. The default browser referrer policy, strict-origin-when-cross-origin, dictates that for cross-origin requests, only the origin is sent [20].

One technique involves leveraging linked sub-resources. If a CSS file hosted on the target domain (B) makes a request to another resource on the same domain, and an attacker's page (A) links to this CSS file, the request initiated by the CSS file will carry B as the Referer. If the Referer check is only validating that the request comes from B, it will pass, even though the request was initiated from A [20].

This extends to JavaScript modules. A JavaScript module loaded from the target domain will set the target domain as the Referer for any requests it makes. The primary constraint for these attacks is often the Same-Origin Policy and CORS configurations, particularly Access-Control-Allow-Credentials: true [20].

Another bypass strategy involves manipulating the Referer header itself. By crafting URLs that appear to contain the trusted domain as a subdomain or part of the path, an attacker might trick regex-based validation checks [21][12].

Content-Type and Method Overrides

Modern applications often process JSON payloads via AJAX requests. The Same-Origin Policy typically prevents cross-origin requests with application/json content types and custom headers without a CORS preflight. However, attackers can exploit lax server-side handling of different MIME types.

If a server accepts text/plain, application/x-www-form-urlencoded, or multipart/form-data for endpoints expecting JSON, attackers can craft HTML forms to send these alternative content types. This can bypass Content-Type checks and trigger CSRF [22][23][3][4][21][18][24].

Method override techniques are also common. Web frameworks sometimes allow overriding HTTP methods (like PUT, DELETE, PATCH) by using parameters such as _method or custom headers (X-HTTP-Method-Override). An attacker can use a POST request with such an override to target endpoints that might not otherwise be subject to CSRF protection for POST requests, or to bypass defenses intended for other methods [25][26][21][18][24].

SameSite Cookie Bypasses

The SameSite cookie attribute is a significant defense against CSRF. By default, modern browsers often enforce Lax or Strict policies. Strict prevents cookies from being sent on any cross-site request. Lax allows cookies to be sent on top-level navigations using GET requests, but blocks them for other cross-site requests, including POSTs [27][28][29][30][31][32][33][34].

However, several bypasses exist:

CSRF Token Validation Flaws

The synchronizer token pattern, where a unique, unpredictable token is embedded in requests, is a primary defense. However, implementations can be flawed:

Other Vulnerability Classes and CSRF

CSRF is often chained with other vulnerabilities:

Specific examples highlight real-world impacts:

Detection and Prevention Strategies

Defending against CSRF requires a layered approach, combining robust server-side validation with modern browser features.

Server-Side Defenses

The most effective server-side defenses are:

Client-Side (Browser) Defenses

Modern browsers offer built-in protections:

Defense in Depth and Best Practices

Tooling for CSRF Detection and Exploitation

Several tools and techniques can aid in identifying and exploiting CSRF vulnerabilities:

When testing, systematically check for the presence and validity of CSRF tokens, test different HTTP methods and content types, and attempt to bypass SameSite cookie restrictions [4][21][31][18].

Recent Developments and Evolving Landscape

The introduction of SameSite=Lax as the default browser policy has significantly reduced the attack surface for CSRF, particularly for POST-based attacks and those relying on cross-origin iframes or img tags [32][33]. However, this shift has also spurred the development of bypass techniques.

The strict-origin-when-cross-origin referrer policy, now common, affects how Referer headers are handled, enabling new bypass vectors through linked sub-resources [20]. Furthermore, the complexity of modern JavaScript applications and APIs, especially those using JSON, presents new challenges. Exploiting misconfigurations in CORS policies or finding alternative content types that the server can still process as JSON remains a viable attack path [22][50].

The shift towards single-page applications (SPAs) and API-driven architectures has also influenced CSRF strategies. While frameworks often include built-in CSRF protection, their implementation details can vary, and vulnerabilities can still arise [57][12].

The ongoing tension between browser security features and web application compatibility continues to shape the CSRF landscape. While SameSite has been a major win, it's not a silver bullet. Developers and security professionals must stay informed about emerging bypasses and maintain a defense-in-depth strategy [53][32][34].

Where to Go Deeper

For those seeking to deepen their understanding and practical skills in CSRF, the following resources are invaluable:

Sources cited in this guide

  1. Cross-site request forgery - Wikipedia — en.wikipedia.org
  2. What Is CSRF? - Palo Alto Networks — paloaltonetworks.com
  3. What is CSRF? Attacks, Mitigation, Prevention - Acunetix — acunetix.com
  4. Cross-Site Request Forgery (CSRF) Attack Guide | Hackviser — hackviser.com
  5. Side-by-Side Comparison of SSRF vs. CSRF | Attaxion — attaxion.com
  6. NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands — thehackernews.com
  7. NASA Ground Control Software Flaw Enables Unauthenticated Commands — infosecurity-magazine.com
  8. The Bug Bounty Guide to Exploiting CSRF Vulnerabilities - YesWeHack — yeswehack.com
  9. CSRF - OWASP Foundation — owasp.org
  10. CSRF Attacks - Rapid7 — rapid7.com
  11. CWE-352: Cross-Site Request Forgery — cwe.mitre.org
  12. Cross-Site Request Forgery Prevention Cheat Sheet | OWASP — cheatsheetseries.owasp.org
  13. https://portswigger.net/web-security/csrf — portswigger.net
  14. How to protect Node.js apps from CSRF attacks — snyk.io
  15. Vulnerabilities in PAC4J software — cert.pl
  16. Avoiding CSRF Attacks with API Design — thedreaming.org
  17. CSRF: Cross Site Request Forgery Example - Imperva — imperva.com
  18. CSRF & Bypasses | Cobalt — cobalt.io
  19. web application - Should login and logout action have CSRF protection? - In — security.stackexchange.com
  20. Bypassing Referer-Based CSRF with strict-origin-when-cross-origin — afine.com
  21. CSRF (Cross Site Request Forgery) | HackTricks — book.hacktricks.xyz
  22. CSRF in the Age of JSON — directdefense.com
  23. CSRF & Bypasses - Cobalt — cobalt.io
  24. 0ang3el/EasyCSRF — github.com
  25. Web Security Academy: CSRF SameSite Lax Bypass via Method Override — medium.com
  26. Lab: SameSite Lax Bypass via Method Override | PortSwigger — portswigger.net
  27. CSRF Protection - Clerk Docs — clerk.com
  28. Preventing CSRF with the SameSite Cookie Attribute — invicti.com
  29. CSRF Attacks: Bypassing SameSite Cookies — blog.cybersamir.com
  30. Advanced CSRF: How to Bypass SameSite Cookie Protections — sajjapremsai.github.io
  31. Bypassing SameSite Cookie Restrictions - CSRF | PortSwigger — portswigger.net
  32. Samesite by Default and What It Means for Bug Bounty Hunters — blog.reconless.com
  33. Samesite by Default and What It Means for Bug Bounty Hunters — blog.reconless.com
  34. Cross-Site Request Forgery is dead! — scotthelme.co.uk
  35. Bypass SameSite Cookies Default to Lax and get CSRF — medium.com
  36. Lab: SameSite Lax Bypass via Cookie Refresh | PortSwigger — portswigger.net
  37. CVE-2026-34394: Wwbn Avideo CSRF Vulnerability — sentinelone.com
  38. Chaining Stored XSS and CSRF in Typemill CMS: A Deep Dive into Attribute Injection — infosecwriteups.com
  39. Self-XSS + CSRF to Stored XSS — medium.com
  40. Vulnerabilities in ATutor software — cert.pl
  41. devanshbatham/Vulnerabilities-Unmasked — github.com
  42. CVE-2026-44613: Turning a CSRF into Silent Unauthorized Actions — ox.security
  43. CVE-2026-40925: CSRF in WWBN AVideo Configuration Endpoint — radar.offseq.com
  44. CVE-2025-12821: WordPress NewsBlogger CSRF Allowing RCE — sentinelone.com
  45. CVE-2025-23797: WP Options Editor CSRF Vulnerability — sentinelone.com
  46. In Praise of CSRF Tokens – Tim MalcomVetter – Medium — medium.com
  47. https://medium.com/@jrozner/wiping-out-csrf-ded97ae7e83f — medium.com
  48. https://www.purehacking.com/blog/andre-onofre-lima/bypassing-csrf-tokens-with-pythons-cgihttpserver — purehacking.com
  49. A Deep Dive into CSRF Protection in Rails – Ruby Inside – Medium — medium.com
  50. https://mixmax.com/blog/modern-csrf — mixmax.com
  51. Cross-site request forgery (CSRF) - Security - MDN Web Docs — developer.mozilla.org
  52. Web Application Security: Anti-CSRF & Cookie SameSite Options — bitsight.com
  53. https://scotthelme.co.uk/csrf-is-dead/ — scotthelme.co.uk
  54. ruby - Sinatra CSRF Authenticity tokens - Stack Overflow — stackoverflow.com
  55. Rapid7 Vulnerability & Exploit Database — rapid7.com
  56. 0xInfection/XSRFProbe — github.com
  57. Modern CSRF Mitigation in Single Page Applications — medium.com
📚 This guide is synthesized from the full text of resources curated in the CSRF library, and refreshed as new material is added.