Description
Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely.
Recommendation
Update the @tootallnate/once package to the latest compatible version. Followings are version details:
Affected version(s): **< 2.0.1 >= 3.0.0, < 3.0.1** Patched version(s): **2.0.1 3.0.1**
References
Could your website be exposed too?
SmartScanner can check your website for @tootallnate/once vulnerable to Incorrect Control Flow Scoping and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding - CVE-2026-30920
- CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function - CVE-2026-26861
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- Backstage vulnerable to potential reading of SCM URLs using built in token - CVE-2026-29185


