Remote Code Execution Vulnerability in Spatie Scotty by Spatie
CVE-2026-93534

5.3MEDIUM

Key Information:

Vendor

Spatie

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-93534?

A vulnerability exists in the Self Update Handler of Spatie Scotty up to version 1.4.2. The function SelfUpdater::update lacks an integrity check for downloaded code, allowing for potential remote code execution. Attackers could exploit this vulnerability by manipulating the update process, resulting in unauthorized code execution on affected systems. To mitigate this risk, users are advised to upgrade to version 1.4.3, which includes a patch for this issue. Ensuring the software is up-to-date is essential for maintaining security and integrity.

Affected Version(s)

Scotty 1.4.0

Scotty 1.4.1

Scotty 1.4.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

summmm (VulDB User)
.