Cross-Site Request Forgery in Apollo GraphQL's Embeddable Tools
CVE-2025-59845
8.2HIGH
What is CVE-2025-59845?
A significant vulnerability exists in the Apollo Studio Embeddable Explorer and Embeddable Sandbox, stemming from inadequate origin validation within their client-side code that processes window.postMessage events. This weakness allows a malicious website to forge messages to the embedding page, potentially enabling unauthorized execution of GraphQL queries or mutations on behalf of authenticated users. The issue, found in versions prior to Apollo Sandbox 2.7.2 and Apollo Explorer 3.7.3, compromises user security by exploiting their logged-in session to interact with GraphQL servers without consent. Updates have been released to address this serious concern.
Affected Version(s)
embeddable-explorer < 2.7.2 < 2.7.2
embeddable-explorer < 3.7.3 < 3.7.3