✨ Strapi MCP is now Generally Available - let your agents manage your Strapi content ✨

3 min read

Axios Supply Chain Incident: Your Strapi Project Is Safe

●March 31, 2026●Updated on June 14, 2026
Axios Supply Chain Incident: Your Strapi Project Is Safe

You may have seen recent reports about a supply chain security concern affecting certain versions of the axios HTTP library (versions greater than 1.14.0). We want to be transparent with the Strapi community: we investigated every repository in the Strapi GitHub organization, and none of them use an affected version of axios.

What happened?

A supply chain incident was identified affecting axios versions above 1.14.0. Supply chain attacks target the software packages that developers depend on, and when a widely-used library like axios is involved, it understandably raises concern.

Is my Strapi project affected?

If you are running a default Strapi installation, the answer is no.

We conducted a thorough audit across every repository in the Strapi GitHub organization. Here is what we found:

In short: no Strapi repository resolves an axios version greater than 1.14.0.

When could you be affected?

There is one scenario where your Strapi project could be at risk:

If you manually installed or upgraded axios to a version above 1.14.0 in your project. This would only happen if you explicitly added or overrode the axios version yourself, for example, for custom plugins, middleware, or API integrations outside of what Strapi provides by default.

If you are unsure, you can check by running the following command in your project directory:

# For yarn projects
yarn why axios

# For npm projects
npm ls axios

# For pnpm projects
pnpm why axios

If the output shows any axios version greater than 1.14.0, you should downgrade to 1.13.6 or lower until an official fix is available.

What should you do?

  • Default Strapi users: No action is needed. Your project is not affected.
  • Custom axios installations: If you added axios independently to your project, check the resolved version and downgrade if it exceeds 1.14.0.
  • Stay updated: Keep your Strapi installation up to date. We actively monitor our dependency tree for security issues.

Our commitment

Security is a priority for the Strapi team. We maintain pinned and locked dependency versions across all of our repositories to prevent exactly this kind of issue from reaching our users. We will continue to monitor the situation and will communicate any changes if the advisory scope evolves.

If you have questions or concerns, please reach out through our community Discord or GitHub discussions.


Note: Our internal Strapi AI and Strapi Cloud repositories were also audited and verified not to be impacted by this incident. We are unable to share specific dependency details for those projects, but can confirm they do not resolve any axios version in the affected range.

Derrick Mehaffy Support Engineer Team Lead

Related Posts

Build an AI App with the Vercel AI SDK and Strapi MCP
TutorialsIntermediate·22 min read

Build an AI App with the Vercel AI SDK and Strapi MCP

Build an AI app with the Vercel AI SDK and Strapi MCP. Add custom MCP tools for related content, link checks, and competitor research with editor approval.

·October 2, 2026
Strapi MCP with Custom Tools and AI Chat
TutorialsBeginner·28 min read

Turn your Strapi content into AI tools with MCP, and add a TanStack AI chat that runs on your machine

Turn on Strapi's MCP server, write one tool that answers over MCP, REST and an admin chat, and run that chat on a local model with TanStack AI and Ollama.

·September 26, 2026
The True TCO of Self-Hosting a Headless CMS
Ecosystem·12 min read

The True TCO of Self-Hosting a Headless CMS

Discover the real cost of self-hosting Strapi 5: infrastructure, DevOps labor, security, migrations, and hidden costs—with a practical TCO checklist.

·September 24, 2026