Skip to content

Update dependency @google/clasp to v3 [SECURITY]#44

Open
balena-renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-google-clasp-vulnerability
Open

Update dependency @google/clasp to v3 [SECURITY]#44
balena-renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-google-clasp-vulnerability

Conversation

@balena-renovate
Copy link
Copy Markdown
Contributor

@balena-renovate balena-renovate Bot commented Mar 14, 2026

This PR contains the following updates:

Package Change Age Confidence
@google/clasp ^2.4.1^3.0.0 age confidence

@​google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script

CVE-2026-4092 / GHSA-hqjg-pww4-pcgq

More information

Details

Impact

Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine.

Patches

Fixed in version 3.2.0

Workarounds
  • Only clone or pull scripts from trusted sources
  • Review the output of the pull and clone commands to verify only expected project files are modified

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

google/clasp (@​google/clasp)

v3.2.0

Compare Source

Features
Bug Fixes
  • Improve validation of credential files (511a060)
  • (SECURITY) prevent path traversal in remote file synchronization (#​1109) (ba6bd66)

v3.1.3

Compare Source

Bug Fixes
  • Add back redirect port to login cmd to be consistent with current documentation (#​1094) (9e8f717)
  • Gemini CLI Extension Path Issue (#​1097) (b466c57)

v3.1.1

Compare Source

Features
Bug Fixes
  • Separated URL from prompt message to help terminals better detect URL to make it clickable (#​1089) (9d59aa1)
  • update Gemini CLI extension config file (#​1092) (62e0dac)

v3.1.0

Compare Source

Features
Bug Fixes
  • handle unknown severity levels in logs (#​1081) (79fb283)
  • Assorted documentation fixes

v2.5.0

Compare Source

Features
Bug Fixes
  • Don't write files on clone if unable to fetch project (#​824) (b3b292a)
  • Rethrow error so command exits with error status (#​1019) (29ac629)

v2.4.2

Compare Source

Bug Fixes
2.4.1 (2021-08-09)
Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from a7dcc9f to 1eea0ad Compare March 26, 2026 16:53
@balena-renovate balena-renovate Bot changed the title Update dependency @google/clasp to v3 [SECURITY] Update dependency @google/clasp to v3 [SECURITY] - autoclosed Mar 27, 2026
@balena-renovate balena-renovate Bot closed this Mar 27, 2026
@balena-renovate balena-renovate Bot deleted the renovate/npm-google-clasp-vulnerability branch March 27, 2026 01:04
@balena-renovate balena-renovate Bot changed the title Update dependency @google/clasp to v3 [SECURITY] - autoclosed Update dependency @google/clasp to v3 [SECURITY] Mar 30, 2026
@balena-renovate balena-renovate Bot reopened this Mar 30, 2026
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 3 times, most recently from 7985df7 to ddf3983 Compare April 1, 2026 10:48
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from 956df59 to 725c133 Compare April 8, 2026 15:02
@balena-renovate balena-renovate Bot changed the title Update dependency @google/clasp to v3 [SECURITY] Update dependency @google/clasp to v3 [SECURITY] - autoclosed Apr 27, 2026
@balena-renovate balena-renovate Bot closed this Apr 27, 2026
@balena-renovate balena-renovate Bot changed the title Update dependency @google/clasp to v3 [SECURITY] - autoclosed Update dependency @google/clasp to v3 [SECURITY] Apr 27, 2026
@balena-renovate balena-renovate Bot reopened this Apr 27, 2026
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from 725c133 to ea59a8a Compare April 27, 2026 20:02
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from ea59a8a to 7481b85 Compare May 7, 2026 15:26
@balena-renovate
Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch 2 times, most recently from e4fb01a to f53768a Compare May 12, 2026 21:03
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from f53768a to 69d2922 Compare May 15, 2026 20:03
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from 69d2922 to 95d8044 Compare May 26, 2026 15:44
Update @google/clasp from 2.4.1 to 3.2.0

Change-type: patch
@balena-renovate balena-renovate Bot force-pushed the renovate/npm-google-clasp-vulnerability branch from 95d8044 to 514db4c Compare May 29, 2026 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants