Skip to content
Vulnerability field guide

Cross-Site Request Forgery

A signed-in browser attaches its session cookie to requests that another site starts. Here is how cross-site request forgery turns that into actions the user never chose, why SameSite cookies alone do not settle it, and how tokens and origin checks close the gap.

2 articles 13 min total Overview to advanced techniques