Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
- Severity:
- High
Description
A Cross-Site Request Forgery (CSRF) vulnerability was identified in Apollo’s Embedded Sandbox and Embedded Explorer.
The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events.
Recommendation
Update the @apollo/explorer package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.7.3
- Patched version(s): 3.7.3
References
Related Issues
- Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - @apollo/sandbox - CVE-2025-59845
- @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation - CVE-2026-26019
- Qwik City has a CSRF Protection Bypass via Content-Type Header Validation - CVE-2026-25151
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
You might also like:
- Tags:
- npm
- @apollo/explorer
Anything's wrong? Let us know Last updated on December 27, 2025


