csrf-csrf@1.0.3 vulnerabilities

A utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express.

Direct Vulnerabilities

Known vulnerabilities in the csrf-csrf package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Cross-site Request Forgery (CSRF)

csrf-csrf is an utility package to help implement stateless CSRF protection using the Double Submit Cookie Pattern in express.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) by using the default cookie name when none is provided, which is prefixed with Host__ instead of __Host-.

How to fix Cross-site Request Forgery (CSRF)?

Upgrade csrf-csrf to version 2.2.1 or higher.

<2.2.1