{"id":"ECHO-318f-4145-6b35","upstream":["CVE-2026-3449","GHSA-vpq2-c234-7xj6"],"severity":[],"modified":"2026-09-28T00:01:38.615Z","affected":[{"package":{"ecosystem":"Echo:npm","name":"@tootallnate/once","purl":"pkg:npm/%40tootallnate%2Fonce"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-3449"},{"type":"WEB","url":"https://github.com/advisories/GHSA-vpq2-c234-7xj6"}]}