This is not CSRF. It uses an iframe containing a pre-filled hacker news submission form effectively causing the user to upvote the already existing story.
It could be argued that hacker news should implement frame busting for additional security, but I don't think it is a huge concern for this site.