PT-2026-95508 · Spatie+1 · Scotty

·

CVE-2026-93533

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions spatie Scotty versions prior to 1.4.5
Description OS command injection is possible via remote attack in the Doctor Command Handler component. The issue exists within the DoctorCommand::checkSshConnectivity() and DoctorCommand::checkRemoteTools() functions located in the app/Commands/DoctorCommand.php file, where improper handling of the host argument allows for the execution of arbitrary operating system commands.
Recommendations As a temporary workaround, restrict access to the DoctorCommand::checkSshConnectivity() and DoctorCommand::checkRemoteTools() functions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93533

Affected Products

Scotty