Skip to content

security: pin axios to 1.13.6 (supply chain attack CVE in 1.14.1)#6

Open
araa47 wants to merge 1 commit intomainfrom
security/pin-axios-1.13.6
Open

security: pin axios to 1.13.6 (supply chain attack CVE in 1.14.1)#6
araa47 wants to merge 1 commit intomainfrom
security/pin-axios-1.13.6

Conversation

@araa47
Copy link
Copy Markdown

@araa47 araa47 commented Mar 31, 2026

URGENT: axios 1.14.1 contains a supply chain attack. Pinning to 1.13.6 to prevent npm from auto-resolving to the malicious version.

Change: package.json: ^1.7.9 → 1.13.6

See https://x.com/wesbos/status/2038809936314892572 for context.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant