Skip to content

Apollo Router Core: Browser Bug Enables Bypass of XS-Search Prevention via Read-Only Cross-Site Request Forgery

Moderate severity GitHub Reviewed Published Mar 24, 2026 in apollographql/router

No open alerts for this advisory

Give feedback on Dependabot alerts