Impact
The vulnerability resides in the DoctorCommand handler of Spatie Scotty versions up to 1.4.4. When the host argument supplied to the checkSshConnectivity or checkRemoteTools methods is manipulated, the command is passed directly to the operating system, allowing an attacker to inject arbitrary shell commands. This flaw enables remote attackers to execute commands on the host running Scotty, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
Spatie Scotty, any deployment using versions 1.4.4 and earlier. The issue is triggered by the DoctorCommand.php component in the Doctor Command Handler.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. With an EPSS score of 1%, the likelihood of exploitation is low but not negligible, and the flaw can be triggered remotely via crafted input. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to interface with Scotty’s command-line interface or API to supply a malicious host value, after which the injected command is executed with the privileges of the Scotty process.
OpenCVE Enrichment