Command Injection Vulnerability in Sourcetree for Windows
CVE-2018-20236
8.8HIGH
What is CVE-2018-20236?
A command injection vulnerability exists in Sourcetree for Windows that permits remote attackers to send crafted URIs, leading to arbitrary code execution. Affected users running versions from 0.5a up to 3.0.9 are at risk, as the vulnerability arises from improper URI handling within the application. Malicious actors can exploit this flaw by delivering specially designed URIs to victims, which Sourcetree processes, potentially compromising the victim's system.
Affected Version(s)
Sourcetree for Windows 0.5a
Sourcetree for Windows < 3.0.10