Clickjacking: stolen clicks through an invisible frame
If any site can put your page in a frame, it can make the frame invisible and line a button of yours up under something the visitor wants to click.
Example
HTTP/1.1 200 OK
Content-Type: text/html
(no X-Frame-Options, no CSP frame-ancestors)Content-Security-Policy: frame-ancestors 'self'
X-Frame-Options: DENYHow it happens
The attacker's page loads yours in a transparent iframe, positioned so that "Delete account", "Confirm payment" or "Allow camera" sits under a harmless-looking button. The visitor is logged in to your site, so the click is real. Any page that changes state with a single click is a target.
How to fix it
Tell the browser who may frame you.
- Content-Security-Policy: frame-ancestors 'self' (or 'none')
- X-Frame-Options: DENY or SAMEORIGIN for older browsers
- Send them as headers on every HTML response
- Ask for confirmation on destructive actions as a second line
How RepoVerse finds it
- ModeratePages can be framed by any site
Another site can load your pages in an invisible frame and trick a logged-in visitor into clicking buttons they cannot see — changing settings, confirming payments.
website · CWE-1021
Questions
- Can I set frame-ancestors in a meta tag?
- No. Browsers ignore frame-ancestors in a <meta> CSP, so it has to be an HTTP header.
- What if my page is meant to be embedded?
- List the sites allowed to embed it in frame-ancestors instead of leaving framing open to everyone.
Related
- Content Security Policy: writing one that actually protectsWrite a Content-Security-Policy that actually stops XSS: why unsafe-inline, unsafe-eval and wildcard sources defeat it, nonces and strict-dynamic, and a policy to start from.
- CSRF: requests your users never meant to sendHow CSRF (CWE-352) makes a logged-in visitor's browser submit forms to your site, and how CSRF tokens and SameSite cookies stop it in Express and other frameworks.
- Security headers checker with a fix for every gapCheck a site's HTTP security headers — Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy — and get the exact line to add for each gap.
Updated 2026-10-11