Remote Code Execution Vulnerability in Sourcetree for Mac and Windows by Atlassian
CVE-2026-21575
7.1HIGH
What is CVE-2026-21575?
A Remote Code Execution vulnerability was identified in versions 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This flaw allows an authenticated attacker to execute arbitrary code, posing significant risks to confidentiality, integrity, and availability of the system. The attacker needs user interaction to exploit this vulnerability effectively. Users are strongly encouraged to upgrade their software to versions greater than or equal to 3.4.13 to mitigate this risk. Atlassian has released guidance on the necessary updates in their release notes and provides download access to the latest versions on their website.
Affected Version(s)
Sourcetree for Mac All versions from 3.4.11 to 3.4.12 inclusive
Sourcetree for Mac All versions from 3.4.13