Loading market data...
← Back to CVE feed

CVE-2026-93533

MEDIUM CVSS 6.3 View on NVD ↗

Description

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Published: Sep 18, 2026 17:17 UTC Modified: Sep 18, 2026 19:14 UTC