Back to Glossary
What is Cross-Site Request Forgery (CSRF)?
Definition
Forces an end user to execute unwanted actions on a web application in which they are currently authenticated.
Security Impact
Unauthorized state-changing requests, such as changing passwords, transferring funds, or updating email addresses.
How to Remediate
Use Anti-CSRF tokens (handled automatically by Next.js Server Actions) and enforce SameSite=Lax/Strict cookie attributes.
Want to automatically detect and block Cross-Site Request Forgery (CSRF) vulnerabilities in your CI/CD pipeline?
Start scanning with Bryxe