Skip to content

Update dependency @google/clasp to v3 [SECURITY]#44

Open
balena-renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-google-clasp-vulnerability
Open

Update dependency @google/clasp to v3 [SECURITY]#44
balena-renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-google-clasp-vulnerability

Conversation

@balena-renovate
Copy link
Copy Markdown
Contributor

@balena-renovate balena-renovate Bot commented Mar 14, 2026

This PR contains the following updates:

Package Change Age Confidence
@google/clasp ^2.4.1^3.0.0 age confidence

@​google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script

CVE-2026-4092 / GHSA-hqjg-pww4-pcgq

More information

Details

Impact

Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.

Patches

Fixed in version 3.2.0

Workarounds
  • Only clone or pull scripts from trusted sources
  • Review the output of the pull and clone commands to verify only expected project files are modified

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/clasp (@​google/clasp)

v3.2.0

Compare Source

Features
Bug Fixes
  • Improve validation of credential files (511a060)
  • (SECURITY) prevent path traversal in remote file synchronization (#​1109) (ba6bd66)

v3.1.3

Compare Source

Bug Fixes
  • Add back redirect port to login cmd to be consistent with current documentation (#​1094) (9e8f717)
  • Gemini CLI Extension Path Issue (#​1097) (b466c57)

v3.1.1

Compare Source

Features
Bug Fixes
  • Separated URL from prompt message to help terminals better detect URL to make it clickable (#​1089) (9d59aa1)
  • update Gemini CLI extension config file (#​1092) (62e0dac)

v3.1.0

Compare Source

Features
Bug Fixes
  • handle unknown severity levels in logs (#​1081) (79fb283)
  • Assorted documentation fixes

v2.5.0

Compare Source

Features
Bug Fixes
  • Don't write files on clone if unable to fetch project (#​824) (b3b292a)
  • Rethrow error so command exits with error status (#​1019) (29ac629)

v2.4.2

Compare Source

Bug Fixes
2.4.1 (2021-08-09)
Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from a7dcc9f to 1eea0ad Compare March 26, 2026 16:53
@balena-renovate balena-renovate Bot changed the title Update dependency @google/clasp to v3 [SECURITY] Update dependency @google/clasp to v3 [SECURITY] - autoclosed Mar 27, 2026
@balena-renovate balena-renovate Bot closed this Mar 27, 2026
@balena-renovate balena-renovate Bot deleted the renovate/npm-google-clasp-vulnerability branch March 27, 2026 01:04
@balena-renovate balena-renovate Bot changed the title Update dependency @google/clasp to v3 [SECURITY] - autoclosed Update dependency @google/clasp to v3 [SECURITY] Mar 30, 2026
@balena-renovate balena-renovate Bot reopened this Mar 30, 2026
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 3 times, most recently from 7985df7 to ddf3983 Compare April 1, 2026 10:48
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from ddf3983 to 956df59 Compare April 7, 2026 15:07
Update @google/clasp from 2.4.1 to 3.2.0

Change-type: patch
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from 956df59 to 725c133 Compare April 8, 2026 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants