Cross-site request forgery (CSRF) forces an authenticated user to perform unintended state-changing actions in a web application. This rule detects when CSRF protection is explicitly disabled or missing from an application.

Why is this an issue?

When CSRF protection is disabled or bypassed, an attacker can trick a logged-in user into submitting requests the application treats as authenticated. The rule flags configurations that disable framework CSRF middleware, exempt specific routes or views, or leave unsafe HTTP methods unprotected.

What is the potential impact?

Unauthorized state changes

An attacker can change passwords, transfer funds, modify data, or perform other privileged operations using the victim’s session.

Account compromise

Successful CSRF attacks can lead to full account takeover when combined with sensitive actions such as email or credential changes.

How to fix it in Laravel

Do not add routes to the $except list on VerifyCsrfToken unless CSRF protection is replaced by an equivalent control.

Code examples

Disabling or bypassing CSRF protection allows an authenticated user’s browser to execute state-changing requests the user did not intend.

Noncompliant code example

use Illuminate\Foundation\Http\Middleware\VerifyCsrfToken as Middleware;

class VerifyCsrfToken extends Middleware
{
    protected $except = [
        'api/*'
    ]; // Noncompliant: disable CSRF protection for a list of routes
}

Compliant solution

use Illuminate\Foundation\Http\Middleware\VerifyCsrfToken as Middleware;

class VerifyCsrfToken extends Middleware
{
    protected $except = [];
}

Remember to add @csrf blade directive to the relevant forms when removing an element from $except. Otherwise the form submission will stop working.

How to fix it in Symfony

Keep CSRF protection enabled on Symfony forms (it is enabled by default).

Code examples

Disabling or bypassing CSRF protection allows an authenticated user’s browser to execute state-changing requests the user did not intend.

Noncompliant code example

use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;

class Controller extends AbstractController {

  public function action() {
    $this->createForm('', null, [
      'csrf_protection' => false, // Noncompliant: disable CSRF protection for a single form
    ]);
  }
}

Compliant solution

use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;

class Controller extends AbstractController {

  public function action() {
    $this->createForm('', null, []);
  }
}

Resources

Documentation

Articles & blog posts

Standards