{"id":"CVE-2026-4092","aliases":["GHSA-hqjg-pww4-pcgq"],"url":"https://o3.security/vulnerability/CVE-2026-4092","summary":"Arbitrary File Write via Path Traversal in Google clasp leading to RCE","details":"Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences.","published":"2026-03-13T15:44:55.099Z","modified":"2026-08-12T03:51:41.459610290Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@google/clasp","fixedVersion":"3.2.0"}],"fix":{"url":"https://github.com/google/clasp/pull/1109","label":"google/clasp#1109"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4092.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4092"},{"type":"FIX","url":"https://github.com/google/clasp/pull/1109"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.459610290Z"}}