Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0671

NIXPKGS-2026-0671
published 3 months, 1 week ago
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package clasp-common-lisp
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Arbitrary File Write via Path Traversal in Google clasp leading to RCE

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences.

Affected products

Clasp
  • ==< 3.2.0

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Upstream patch: https://github.com/google/clasp/commit/ba6bd666fe74de54950122b5d92ecf1dcc02a9d3