PT-2026-25324 · Npm+1 · @Google/Clasp+1

Leekiyoon-Sec

·

Published

2026-03-13

·

Updated

2026-03-16

·

CVE-2026-4092

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clasp versions prior to 3.2.0
Description A path traversal issue exists in Clasp, potentially allowing a remote attacker to execute code on the developer's machine. This occurs through a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences. The issue allows an attacker to modify files outside the project directory, leading to potential remote code execution.
API Endpoints No API endpoints are mentioned in the provided descriptions.
Vulnerable Parameters or Variables Filenames within Google Apps Script projects are vulnerable.
Recommendations Update Clasp to version 3.2.0 or later. Only clone or pull scripts from trusted sources. Review the output of the pull and clone commands to verify only expected project files are modified.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-4092
GHSA-HQJG-PWW4-PCGQ

Affected Products

@Google/Clasp
Clasp