CVE-2026-93534 Details
Description
A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744. It is advisable to upgrade the affected component.
A vulnerability exists in Spatie Scotty versions through 1.4.2, specifically within the Self Update Handler component. The issue arises in the SelfUpdater::update function, located in app/Updater/SelfUpdater.php. This vulnerability allows the download of code without any integrity verification, enabling remote code execution. The problem has been addressed in version 1.4.3, which includes a patch that verifies the authenticity of the downloaded file before applying the update.
Users are advised to upgrade to Spatie Scotty version 1.4.3 or later. Instructions for downloading the latest version are available on the Spatie Scotty GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/spatie/scotty/issues/21 | CISA-ADP | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/spatie/scotty/ | [email protected] | ProductSource CodeVendor |
| https://github.com/spatie/scotty/commit/4b4e11bfc98e3a2159bb2b3d9b040293fcc44744 | [email protected] | Source CodeVendor |
| https://github.com/spatie/scotty/issues/21 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/spatie/scotty/releases/tag/1.4.3 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-93534 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/943918 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/407451 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/407451/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-494 | Download of Code Without Integrity Check | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| spatie Scotty | 1.4.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion