πŸš€ Submit a Challenge β€” SecDim AppSec Village CTF at DEF CON 34 and Win a ROG Xbox Ally

Challenge Release: Ruby on Rails Cross-Site Request Forgery Incident

News1 min read

In 2025, a critical vulnerability in Ruby on Rails Cross-Site Request Forgery (CSRF) protection mechanism has been identified, affecting all versions since the 2022/2023 β€œfix” and persisting in the current implementation. This flaw undermines the framework’s ability to secure applications against CSRF attacks, potentially allowing attackers to forge or replay tokens and execute unauthorized actions on behalf of users.

:light_bulb: We made challenges for this vulnerability, taking inspiration from the Ruby on Rails CSRF Flaw Incident, also covered by CyberPress

Available Now

:police_car_light: Limited time Weekly Incident Game

:backhand_index_pointing_right: SecDim Play - Weekly Incident Game

In catalog:

Questions or comments? Discuss this post on SecDim Community β†’

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing β€” fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.