Back to Glossary

What is Cross-Site Request Forgery (CSRF)?

Definition

Forces an end user to execute unwanted actions on a web application in which they are currently authenticated.

Security Impact

Unauthorized state-changing requests, such as changing passwords, transferring funds, or updating email addresses.

How to Remediate

Use Anti-CSRF tokens (handled automatically by Next.js Server Actions) and enforce SameSite=Lax/Strict cookie attributes.

Want to automatically detect and block Cross-Site Request Forgery (CSRF) vulnerabilities in your CI/CD pipeline?

Start scanning with Bryxe
Put the definition into practice: security field guides →