CVE-2026-93534
Published:September 18, 2026
Updated:October 09, 2026
A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without integrity check. It is possible to launch the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The name of the patch is 4b4e11bfc98e3a2159bb2b3d9b040293fcc44744. It is advisable to upgrade the affected component.
Affected Packages
https://github.com/spatie/scotty.git (GITHUB):
Affected version(s) >=1.4.0 <1.4.3Fix Suggestion:
Update to version 1.4.3spatie/scotty (PHP):
Affected version(s) >=1.4.0 <1.4.3Fix Suggestion:
Update to version 1.4.3Related Resources (10)
Do you need more information?
Contact UsCVSS v4
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
Exploit Maturity
NOT DEFINED
CVSS v3
Base Score:
6.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW
Exploit Maturity
NOT DEFINED
Weakness Type (CWE)
Download of Code Without Integrity Check
EPSS
Base Score:
0.21