{"id":"CVE-2026-93533","title":"A vulnerability was determined in spatie Scotty up to 1.4.4","summary":"A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","cwe":["CWE-77","CWE-78"],"vendor":"spatie","product":"Scotty","affected":["Scotty 1.4.0","Scotty 1.4.1","Scotty 1.4.2","Scotty 1.4.3","Scotty 1.4.4"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:14:56.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93533","references":[{"url":"https://github.com/spatie/scotty/","label":"cna@vuldb.com"},{"url":"https://github.com/spatie/scotty/issues/20","label":"cna@vuldb.com"},{"url":"https://github.com/spatie/scotty/pull/22","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-93533","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/943917","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/407450","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/407450/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-18T16:45:41.412Z","epss":0.01114,"epssPercentile":0.6409,"slug":"CVE-2026-93533","body":"## Overview\n\nA vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}