Description
A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744. It is advisable to upgrade the affected component.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the SelfUpdater component of spatie Scotty, specifically the update function in SelfUpdater.php. The code that performs the download of the update file does not validate the integrity of the retrieved content, allowing an attacker to supply arbitrary code that will be executed when the self update is performed. Because the flaw affects the downloader itself, the weakness is a classic ‘download of untrusted code without validation’ (CWE‑494) and leads to potential remote code execution on the host running the framework.

Affected Systems

This issue affects all releases of spatie Scotty up to and including version 1.4.2. The fixed version 1.4.3 incorporates the commit 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744, which adds an integrity check to the download routine. Any deployment of spatie Scotty that relies on the Self Updater component and has not been upgraded to 1.4.3 or later is vulnerable.

Risk and Exploitability

The CVSS base score of 5.3 indicates a medium severity when taking into account confidentiality, integrity, and availability considerations. The EPSS score of less than 1 % suggests that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw is exploitable over the network without authentication, meaning that a remote attacker can trigger the download of malicious payloads by invoking the self‑update endpoint or otherwise invoking the vulnerable function.

Generated by OpenCVE AI on September 19, 2026 at 16:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade spatie Scotty to version 1.4.3 or newer, which enforces integrity checking in the self‑updater.
  • If an upgrade is not immediately feasible, replace the SelfUpdater component with the patched commit 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744 to ensure the download routine verifies authenticity.
  • Restrict access to the self‑update functionality so that only trusted administrators can trigger it, and disable the Self Updater feature if the application does not require it.

Generated by OpenCVE AI on September 19, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744. It is advisable to upgrade the affected component.
Title spatie Scotty Self Update SelfUpdater.php update code download
First Time appeared Spatie
Spatie scotty
Weaknesses CWE-494
CPEs cpe:2.3:a:spatie:scotty:*:*:*:*:*:*:*:*
Vendors & Products Spatie
Spatie scotty
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T17:14:11.112Z

Reserved: 2026-09-18T08:54:30.878Z

Link: CVE-2026-93534

cve-icon Vulnrichment

Updated: 2026-09-18T17:12:10.998Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T17:17:06.290

Modified: 2026-09-18T19:14:56.310

Link: CVE-2026-93534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:17Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check