CVE-2026-4092

HIGH EPSS 36.9%
Published Mar 13, 20263mo ago · Modified Apr 14, 20262mo ago
8.7 CVSS 4.0
High
Find Similar
Published Mar 13, 2026 3mo ago
Last Modified Apr 14, 2026 2mo ago

Description

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences.

CVSS Details

Base Score
8.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction P
Scope X

Threat Intelligence

EPSS Exploit Probability
36.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-22 Path Traversal Resource Mgmt

Affected Products 1

VendorProductVersionRange
googleclasp* <3.2.0

References 1

  • github.com https://github.com/google/clasp/pull/1109
    Issue TrackingPatch

Remediation

  • github.com https://github.com/google/clasp/pull/1109
    Issue TrackingPatch