CVE-2026-93533 | spatie Scotty up to 1.4.4 Doctor Command DoctorCommand.php checkRemoteTools host os command injection (Issue 20)

SecurityVulns

A vulnerability was found in spatie Scotty up to 1.4.4. It has been rated as critical. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection.

The identification of this vulnerability is CVE-2026-93533. It is possible to initiate the attack remotely. There is no exploit available.

The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More