Security Advisories์ถœ์ฒ˜: GitHub Security Advisories์กฐํšŒ์ˆ˜ 2

[@google/clasp] @google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script

By GitHub
2026๋…„ 3์›” 14์ผ
**[@google/clasp] @google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script**

Impact Allows an attacker to perform a "Path Traversal" attack to modify files outside the projects directory, potentially allowing for running attacker code on the developer's machine. Patches Fixed in version 3.2.0 Workarounds Only clone or pull scripts from trusted sources Review the output of the pull and clone commands to verify only expected project files are modified References https://github.com/google/clasp/security/advisories/GHSA-hqjg-pww4-pcgq https://nvd.nist.gov/vuln/detail/CVE-2026-4092 https://github.com/google/clasp/pull/1109 https://github.com/google/clasp/commit/ba6bd666fe74de54950122b5d92ecf1dcc02a9d3 https://github.com/google/clasp/releases/tag/v3.2.0 https://github.com/advisories/GHSA-hqjg-pww4-pcgq

---

**[devsupporter ํ•ด์„ค]**

์ด ๊ธฐ์‚ฌ๋Š” GitHub Security Advisories์—์„œ ์ œ๊ณตํ•˜๋Š” ์ตœ์‹  ๊ฐœ๋ฐœ ๋™ํ–ฅ์ž…๋‹ˆ๋‹ค. ๊ด€๋ จ ๋„๊ตฌ๋‚˜ ๊ธฐ์ˆ ์— ๋Œ€ํ•ด ๋” ์•Œ์•„๋ณด์‹œ๋ ค๋ฉด ์›๋ณธ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.