Challenge Release: Ruby on Rails Cross-Site Request Forgery Incident
In 2025, a critical vulnerability in Ruby on Rails Cross-Site Request Forgery (CSRF) protection mechanism has been identified, affecting all versions since the 2022/2023 βfixβ and persisting in the current implementation. This flaw undermines the frameworkβs ability to secure applications against CSRF attacks, potentially allowing attackers to forge or replay tokens and execute unauthorized actions on behalf of users.
We made challenges for this vulnerability, taking inspiration from the Ruby on Rails CSRF Flaw Incident, also covered by CyberPress
Available Now
Limited time Weekly Incident Game
SecDim Play - Weekly Incident Game
In catalog:
