Description
A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: 1.4% Low
KEV: No
Impact: Remote OS Command Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the DoctorCommand handler of Spatie Scotty versions up to 1.4.4. When the host argument supplied to the checkSshConnectivity or checkRemoteTools methods is manipulated, the command is passed directly to the operating system, allowing an attacker to inject arbitrary shell commands. This flaw enables remote attackers to execute commands on the host running Scotty, potentially compromising confidentiality, integrity, and availability of the system.

Affected Systems

Spatie Scotty, any deployment using versions 1.4.4 and earlier. The issue is triggered by the DoctorCommand.php component in the Doctor Command Handler.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. With an EPSS score of 1%, the likelihood of exploitation is low but not negligible, and the flaw can be triggered remotely via crafted input. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to interface with Scotty’s command-line interface or API to supply a malicious host value, after which the injected command is executed with the privileges of the Scotty process.

Generated by OpenCVE AI on September 19, 2026 at 23:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Spatie Scotty to a version that incorporates the fix from pull request #22 once it is merged into the main branch
  • If an update is not yet available, immediately restrict or disable the checkSshConnectivity and checkRemoteTools functionality in production environments
  • Implement input validation that sanitizes or rejects host arguments containing shell metacharacters before they are passed to the shell command executor

Generated by OpenCVE AI on September 19, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance.
Title spatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injection
First Time appeared Spatie
Spatie scotty
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:spatie:scotty:*:*:*:*:*:*:*:*
Vendors & Products Spatie
Spatie scotty
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-23T16:15:47.740Z

Reserved: 2026-09-18T08:54:25.619Z

Link: CVE-2026-93533

cve-icon Vulnrichment

Updated: 2026-09-23T16:15:07.513Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:17:06.080

Modified: 2026-09-23T17:17:19.973

Link: CVE-2026-93533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')