@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script
Description
Published by the National Vulnerability Database
Mar 13, 2026
Published to the GitHub Advisory Database
Mar 13, 2026
Reviewed
Mar 13, 2026
Last updated
Mar 16, 2026
Impact
Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.
Patches
Fixed in version 3.2.0
Workarounds
pullandclonecommands to verify only expected project files are modifiedReferences