Cross-Site Request Forgery in Apollo GraphQL's Embeddable Tools
CVE-2025-59845

8.2HIGH

Key Information:

Vendor
CVE Published:
26 September 2025

What is CVE-2025-59845?

A significant vulnerability exists in the Apollo Studio Embeddable Explorer and Embeddable Sandbox, stemming from inadequate origin validation within their client-side code that processes window.postMessage events. This weakness allows a malicious website to forge messages to the embedding page, potentially enabling unauthorized execution of GraphQL queries or mutations on behalf of authenticated users. The issue, found in versions prior to Apollo Sandbox 2.7.2 and Apollo Explorer 3.7.3, compromises user security by exploiting their logged-in session to interact with GraphQL servers without consent. Updates have been released to address this serious concern.

Affected Version(s)

embeddable-explorer < 2.7.2 < 2.7.2

embeddable-explorer < 3.7.3 < 3.7.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59845 : Cross-Site Request Forgery in Apollo GraphQL's Embeddable Tools