CVE-2026-93534

Source
https://cve.org/CVERecord?id=CVE-2026-93534
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93534.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93534
Published
2026-09-18T16:30:13Z
Modified
2026-09-20T11:47:30Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
spatie Scotty Self Update SelfUpdater.php update code download
Details

A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744. It is advisable to upgrade the affected component.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-494"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93534.json"
}
References

Affected packages

Git / github.com/spatie/scotty

Affected ranges

Type
GIT
Repo
https://github.com/spatie/scotty
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.4.0"
        },
        {
            "last_affected": "1.4.0"
        },
        {
            "introduced": "1.4.1"
        },
        {
            "last_affected": "1.4.1"
        },
        {
            "introduced": "1.4.2"
        },
        {
            "last_affected": "1.4.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.4.0
1.4.1
1.4.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93534.json"