Vulnerabilities/

@tootallnate/once vulnerable to Incorrect Control Flow Scoping

Severity:
Low

Description

Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely.

Recommendation

Update the @tootallnate/once package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@tootallnate/once
Anything's wrong? Let us know Last updated on May 21, 2026