This repo hosts the source for Apollo Studio's Embeddable Sandbox
@apollo/[email protected] has vulnerabilities — update to latest
Update to >= 3.7.3 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2025-59845 | Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass | 3.7.3 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/@apollo/sandboxFirst published · 2022-06-30T23:08:42.566Z
Last updated · 2026-01-08T21:00:09.518Z