CVE-2026-93534 | spatie Scotty up to 1.4.2 Self Update SelfUpdater.php SelfUpdater::update code download (Issue 21)
A vulnerability categorized as critical has been discovered in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check.
This vulnerability is referenced as CVE-2026-93534. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More