Impact
The vulnerability resides in the SelfUpdater component of spatie Scotty, specifically the update function in SelfUpdater.php. The code that performs the download of the update file does not validate the integrity of the retrieved content, allowing an attacker to supply arbitrary code that will be executed when the self update is performed. Because the flaw affects the downloader itself, the weakness is a classic ‘download of untrusted code without validation’ (CWE‑494) and leads to potential remote code execution on the host running the framework.
Affected Systems
This issue affects all releases of spatie Scotty up to and including version 1.4.2. The fixed version 1.4.3 incorporates the commit 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744, which adds an integrity check to the download routine. Any deployment of spatie Scotty that relies on the Self Updater component and has not been upgraded to 1.4.3 or later is vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity when taking into account confidentiality, integrity, and availability considerations. The EPSS score of less than 1 % suggests that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw is exploitable over the network without authentication, meaning that a remote attacker can trigger the download of malicious payloads by invoking the self‑update endpoint or otherwise invoking the vulnerable function.
OpenCVE Enrichment