
Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container environment.
Demo to verify the behavior of axios vulnerability CVE-2023-45857
npm run dev on the app containerXSRF-TOKEN is set in the Cookie using the browser's developer tools
CREDENTIAL_TOKENwhoami.localhost/api has the header x-xsrf-token with the value CREDENTIAL_TOKEN