Attack  ·  Glossary

Cross-Site Request Forgery (CSRF) Against AI Agents

An attack where simply visiting a malicious or booby-trapped webpage causes your browser to secretly send a command to an AI tool running on your own computer — because that tool trusts any request that appears to come from your machine, without checking who really asked. No malware download or click is needed; browsing alone can trigger it.
Many local AI coding tools and agent runtimes were built assuming only the developer's own commands would reach them, so this attack class turns ordinary web browsing into a silent path to full code execution on developer machines.
Track this in the live feed See how this plays out in real AI security and governance developments.
Open the feed →