Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - @apollo/sandbox
- Severity:
- High
Description
A Cross-Site Request Forgery (CSRF) vulnerability was identified in Apollo’s Embedded Sandbox and Embedded Explorer.
The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events.
Recommendation
Update the @apollo/sandbox package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.7.2
- Patched version(s): 2.7.2
References
Related Issues
- Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass - CVE-2025-59845
- @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation - CVE-2026-26019
- Qwik City has a CSRF Protection Bypass via Content-Type Header Validation - CVE-2026-25151
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
You might also like:
- Tags:
- npm
- @apollo/sandbox
Anything's wrong? Let us know Last updated on December 27, 2025


