Junglewise Threat Intelligence

CVE-2026-4092: Google clasp path traversal in clone and pull

CVE-2026-4092 · Severity: medium · CVSS 4 · Published 2026-03-13

Vendors: Google, npm.

Executive brief

Google's clasp tool, used by developers to manage Google Apps Script projects from the command line, contains a path traversal vulnerability that allows an attacker to write files outside the intended project directory when a developer clones or pulls a malicious script. An attacker could exploit this to execute arbitrary code on a developer's machine by crafting a malicious Apps Script project.

Technical details

The vulnerability is a path traversal attack (CWE-22) in the clone and pull commands of @google/clasp, a tool for managing Google Apps Script projects locally. The vulnerability allows an attacker to craft a malicious Apps Script project that, when cloned or pulled by a developer, writes files outside the project's intended directory structure. This occurs because the tool does not properly validate or sanitize file paths during the clone/pull operations. The attack requires user interaction (the developer must perform a clone or pull operation), but no authentication or special privileges are needed. An attacker can achieve arbitrary code execution on the developer's machine by placing executable files or scripts in unexpected locations (e.g., startup directories). The vulnerability is fixed in version 3.2.0.

Affected products

  • Google clasp before 3.2.0

Timeline

  • 2026-03-13: disclosed
  • 2026-03-13: patched: fixed in version 3.2.0

References