PT-2026-95509 · Spatie+1 · Scotty

·

CVE-2026-93534

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions spatie Scotty versions prior to 1.4.3
Description A remote attack is possible through the Self Update Handler component. The SelfUpdater::update() function in the app/Updater/SelfUpdater.php file allows the download of code without an integrity check, which could lead to the execution of unauthorized code.
Recommendations Upgrade to version 1.4.3. As a temporary mitigation, restrict access to the SelfUpdater::update() function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93534

Affected Products

Scotty