Vulnerabilities/

Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass

Severity:
High

Description

A Cross-Site Request Forgery (CSRF) vulnerability was identified in Apollo’s Embedded Sandbox and Embedded Explorer.

The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events.

Recommendation

Update the @apollo/explorer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@apollo/explorer
Anything's wrong? Let us know Last updated on December 27, 2025