OS Command Injection Vulnerability in Spatie Scotty by Spatie
CVE-2026-93533
5.3MEDIUM
What is CVE-2026-93533?
A vulnerability has been identified in Spatie Scotty versions up to 1.4.4 that affects the Doctor Command Handler. This issue specifically resides in the handling of the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools, where manipulation of the 'host' argument can lead to a remote OS command injection. This type of attack allows an unauthorized user to execute arbitrary commands on the target system. A pull request intended to remediate this vulnerability is currently pending acceptance.
Affected Version(s)
Scotty 1.4.0
Scotty 1.4.1
Scotty 1.4.2
