CVE-2026-4092: Google Clasp
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences.
Affected products
- Google Clasp: before 3.2.0 (fixed in 3.2.0)
Published 2026-03-13. Last modified 2026-06-17.