PT-2026-25324 · Npm+1 · @Google/Clasp+1
Leekiyoon-Sec
·
Published
2026-03-13
·
Updated
2026-03-16
·
CVE-2026-4092
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Clasp versions prior to 3.2.0
Description
A path traversal issue exists in Clasp, potentially allowing a remote attacker to execute code on the developer's machine. This occurs through a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences. The issue allows an attacker to modify files outside the project directory, leading to potential remote code execution.
API Endpoints
No API endpoints are mentioned in the provided descriptions.
Vulnerable Parameters or Variables
Filenames within Google Apps Script projects are vulnerable.
Recommendations
Update Clasp to version 3.2.0 or later.
Only clone or pull scripts from trusted sources.
Review the output of the
pull and clone commands to verify only expected project files are modified.Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Google/Clasp
Clasp