3.7.4
4 years ago
8 months ago
Known vulnerabilities in the @apollo/explorer package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@apollo/explorer is a This repo hosts the source for Apollo Studio's Embeddable Explorer Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) via missing origin validation in the ##Workaround This vulnerability can be mitigated by ensuring that production deployments set the environment variable NODE_ENV=production to avoid unintentionally serving embedded Sandbox. How to fix Cross-site Request Forgery (CSRF)? Upgrade | <3.7.3 |