Cross-site request forgery in server-runtime - #VU134927
Published: June 19, 2026
server-runtime
Detailed vulnerability description
The vulnerability allows a remote attacker to perform cross-site request forgery actions.
The vulnerability exists due to cross-site request forgery in document request handling when processing PUT, PATCH, or DELETE requests in framework mode. A remote attacker can cause the victim's browser to send a crafted cross-site request to perform cross-site request forgery actions.
This issue does not affect applications using declarative mode or data mode.