Executive brief
fastify-csrf is a Node.js plugin that protects web applications built with Fastify from cross-site request forgery (CSRF) attacks. Versions before 3.0.0 contain multiple CSRF protection weaknesses: cookies lack the httpOnly flag, allowing JavaScript to access the token, and tokens can be extracted via GET query parameters, making them vulnerable to interception. An attacker could forge requests on behalf of authenticated users, potentially compromising account security and application integrity.
Technical details
The vulnerability is a cross-site request forgery (CSRF) protection bypass in fastify-csrf stemming from insecure default cookie configuration and improper token handling. The root causes are: (1) cookies were generated without the httpOnly flag, making tokens accessible to JavaScript and vulnerable to XSS-based theft, and (2) CSRF tokens were transmitted as GET query parameters, which are logged in browser history and server logs. The attack requires user interaction (victim must visit a malicious site while authenticated to the vulnerable application) but has no authentication or special privilege requirements for the attacker. An attacker can forge state-changing requests on behalf of legitimate users, potentially modifying data or performing unauthorized actions. Version 3.0.0 and later remediate these issues by adding httpOnly flag by default and removing query parameter token transmission by default.
Affected products
- Fastify fastify-csrf < 3.0.0
Timeline
- 2021-01-19: disclosed: Published on NVD
- 2021-01-20: advisory: GHSA advisory published
- 2020-12-11: patched: Version 3.0.0 released with fixes