CVE-2026-93533

Source
https://cve.org/CVERecord?id=CVE-2026-93533
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93533.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93533
Published
2026-09-18T16:15:10Z
Modified
2026-09-20T11:47:29Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection
Details

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-77",
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93533.json"
}
References

Affected packages

Git / github.com/spatie/scotty

Affected ranges

Type
GIT
Repo
https://github.com/spatie/scotty
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.4.0"
        },
        {
            "last_affected": "1.4.0"
        },
        {
            "introduced": "1.4.1"
        },
        {
            "last_affected": "1.4.1"
        },
        {
            "introduced": "1.4.2"
        },
        {
            "last_affected": "1.4.2"
        },
        {
            "introduced": "1.4.3"
        },
        {
            "last_affected": "1.4.3"
        },
        {
            "introduced": "1.4.4"
        },
        {
            "last_affected": "1.4.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93533.json"