---
id: CVE-2026-93533
title: A vulnerability was determined in spatie Scotty up to 1.4.4
summary: >-
  A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the
  function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools
  of the file app/Commands/DoctorCommand.php of the component Doctor Command
  Handler…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
vendor: spatie
product: Scotty
affected:
  - Scotty 1.4.0
  - Scotty 1.4.1
  - Scotty 1.4.2
  - Scotty 1.4.3
  - Scotty 1.4.4
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:14:56.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93533'
references:
  - url: 'https://github.com/spatie/scotty/'
    label: cna@vuldb.com
  - url: 'https://github.com/spatie/scotty/issues/20'
    label: cna@vuldb.com
  - url: 'https://github.com/spatie/scotty/pull/22'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-93533'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/943917'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407450'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/407450/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-18T16:45:41.412Z'
epss: 0.01114
epssPercentile: 0.6409
---

## Overview

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
