Description
A Cross-Site Request Forgery (CSRF) vulnerability was identified in Apollo’s Embedded Sandbox and Embedded Explorer.
The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events.
Recommendation
Update the @apollo/sandbox package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.7.2
- Patched version(s): 2.7.2
References
Could your website be exposed too?
SmartScanner can check your website for Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - @apollo/sandbox and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - CVE-2025-59845
- @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation - CVE-2026-26019
- Qwik City has a CSRF Protection Bypass via Content-Type Header Validation - CVE-2026-25151
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862


