Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victim’s browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victim’s cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 29 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apollographql
Apollographql apollo Explorer Apollographql apollo Sandbox |
|
Vendors & Products |
Apollographql
Apollographql apollo Explorer Apollographql apollo Sandbox |
Fri, 26 Sep 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victim’s browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victim’s cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3. | |
Title | Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass | |
Weaknesses | CWE-346 CWE-352 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-29T15:02:04.057Z
Reserved: 2025-09-22T14:34:03.472Z
Link: CVE-2025-59845

Updated: 2025-09-29T15:01:40.967Z

Status : Awaiting Analysis
Published: 2025-09-26T23:15:31.640
Modified: 2025-09-29T19:34:10.030
Link: CVE-2025-59845

No data.