Skip to content

Update dependency @google/clasp to v3 [SECURITY] - #63

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-google-clasp-vulnerability
Open

Update dependency @google/clasp to v3 [SECURITY]#63
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-google-clasp-vulnerability

Conversation

@renovate

@renovate renovate Bot commented May 9, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@google/clasp ^2.4.2^3.0.0 age confidence

@​google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script

CVE-2026-4092 / GHSA-hqjg-pww4-pcgq

More information

Details

Impact

Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.

Patches

Fixed in version 3.2.0

Workarounds
  • Only clone or pull scripts from trusted sources
  • Review the output of the pull and clone commands to verify only expected project files are modified

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/clasp (@​google/clasp)

v3.2.0

Compare Source

Features
Bug Fixes
  • Improve validation of credential files (511a060)
  • (SECURITY) prevent path traversal in remote file synchronization (#​1109) (ba6bd66)

v3.1.3

Compare Source

Bug Fixes
  • Add back redirect port to login cmd to be consistent with current documentation (#​1094) (9e8f717)
  • Gemini CLI Extension Path Issue (#​1097) (b466c57)

v3.1.1

Compare Source

Features
Bug Fixes
  • Separated URL from prompt message to help terminals better detect URL to make it clickable (#​1089) (9d59aa1)
  • update Gemini CLI extension config file (#​1092) (62e0dac)

v3.1.0

Compare Source

Features
Bug Fixes
  • handle unknown severity levels in logs (#​1081) (79fb283)
  • Assorted documentation fixes

v2.5.0

Compare Source

Features
Bug Fixes
  • Don't write files on clone if unable to fetch project (#​824) (b3b292a)
  • Rethrow error so command exits with error status (#​1019) (29ac629)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from cfbc529 to d15a691 Compare May 18, 2026 18:56
@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from 78e02d5 to 571c3b1 Compare June 1, 2026 21:44
@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from 571c3b1 to 26e3d44 Compare June 11, 2026 15:04
@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from f1eaaf4 to d425dd1 Compare July 16, 2026 16:50
@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from c96b2bb to 69c06fc Compare July 24, 2026 15:07
@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from 69c06fc to e17d74b Compare July 30, 2026 18:30
@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from e17d74b to 5ab45e7 Compare August 12, 2026 03:47
@renovate
renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from 5ab45e7 to 5f67a04 Compare August 14, 2026 19:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants