Cross-Site Request Forgery in Apollo GraphQL's Embeddable Tools
CVE-2025-59845
What is CVE-2025-59845?
A significant vulnerability exists in the Apollo Studio Embeddable Explorer and Embeddable Sandbox, stemming from inadequate origin validation within their client-side code that processes window.postMessage events. This weakness allows a malicious website to forge messages to the embedding page, potentially enabling unauthorized execution of GraphQL queries or mutations on behalf of authenticated users. The issue, found in versions prior to Apollo Sandbox 2.7.2 and Apollo Explorer 3.7.3, compromises user security by exploiting their logged-in session to interact with GraphQL servers without consent. Updates have been released to address this serious concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
embeddable-explorer < 2.7.2 < 2.7.2
embeddable-explorer < 3.7.3 < 3.7.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
