{"id":"GHSA-hqjg-pww4-pcgq","summary":"@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script","details":"### Impact\nAllows an attacker to perform a \"Path Traversal\" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.\n\n### Patches\nFixed in version 3.2.0\n\n### Workarounds\n* Only clone or pull scripts from trusted sources\n* Review the output of the `pull` and `clone` commands to verify only expected project files are modified","aliases":["CVE-2026-4092"],"modified":"2026-03-16T17:16:39.711134Z","published":"2026-03-13T20:57:29Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-13T20:57:29Z","nvd_published_at":"2026-03-13T19:55:13Z"},"references":[{"type":"WEB","url":"https://github.com/google/clasp/security/advisories/GHSA-hqjg-pww4-pcgq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4092"},{"type":"WEB","url":"https://github.com/google/clasp/pull/1109"},{"type":"WEB","url":"https://github.com/google/clasp/commit/ba6bd666fe74de54950122b5d92ecf1dcc02a9d3"},{"type":"PACKAGE","url":"https://github.com/google/clasp"},{"type":"WEB","url":"https://github.com/google/clasp/releases/tag/v3.2.0"}],"affected":[{"package":{"name":"@google/clasp","ecosystem":"npm","purl":"pkg:npm/%40google/clasp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hqjg-pww4-pcgq/GHSA-hqjg-pww4-pcgq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}