Skip to content

[GHSA-vpq2-c234-7xj6] @tootallnate/once vulnerable to Incorrect Control Flow Scoping#7638

Open
orien wants to merge 1 commit into
orien/advisory-improvement-7638from
orien-GHSA-vpq2-c234-7xj6
Open

[GHSA-vpq2-c234-7xj6] @tootallnate/once vulnerable to Incorrect Control Flow Scoping#7638
orien wants to merge 1 commit into
orien/advisory-improvement-7638from
orien-GHSA-vpq2-c234-7xj6

Conversation

@orien
Copy link
Copy Markdown

@orien orien commented May 11, 2026

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • References
  • Severity

Comments
https://github.com/TooTallNate/once/releases/tag/v2.0.1 has been released with a fix.

Note

I couldn't submit the form without removing the last section of the severity vector string.

Copilot AI review requested due to automatic review settings May 11, 2026 06:42
@github-actions github-actions Bot changed the base branch from main to orien/advisory-improvement-7638 May 11, 2026 06:43
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the OSV advisory record for GHSA-vpq2-c234-7xj6 affecting @tootallnate/once, reflecting new fix/release information and revised scoring metadata.

Changes:

  • Updates the advisory’s affected version ranges to include a fix in the 2.x line (fixed in 2.0.1) and clarifies the 3.0.0 → 3.0.1 affected window.
  • Adjusts the CVSS representation to include only CVSS v4 (and removes the prior CVSS v3 entry).
  • Adds additional upstream references (commit + release tags) and updates the database-specific severity label.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines 11 to 15
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
}
Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I didn't intend to edit the severity. The form wouldn't submit until I removed the /E:P suffix. I didn't intend for the CVSS_V3 severity to be removed either.

Comment on lines -68 to +98
"severity": "LOW",
"severity": "MODERATE",
Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I didn't intend to change the severity. Although the sync page does report medium: https://security.snyk.io/vuln/SNYK-JS-TOOTALLNATEONCE-15250612

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants