Description
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows.

This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction.

Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

* Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13



See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives).

This vulnerability was reported via our Bug Bounty program.
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Remote Code Execution flaw that allows an authenticated attacker to run arbitrary code with high impact on confidentiality, integrity, and availability. The weakness is classified as CWE-94, indicating that invalid or malicious input can cause code compilation or execution within the application.

Affected Systems

Atlassian Sourcetree for Mac and Windows, version 3.4.11 is confirmed vulnerable. The CVE description indicates that the fix begins at release 3.4.13, so we infer that intermediate releases such as 3.4.12 are likely vulnerable, as they are before the fixed version and no explicit statement of remediation exists for them. The affected platforms are macOS and Windows, as indicated by the provided CPE taxonomy.

Risk and Exploitability

The CVSS score of 7.1 indicates medium to high severity, while the EPSS score of less than 1 percent suggests a low probability of exploitation at present. The vulnerability requires user interaction and authenticated access, implying that the attacker must have valid login credentials. It is not listed in the CISA KEV catalog, but vendors recommend immediate patching to mitigate the risk.

Generated by OpenCVE AI on August 5, 2026 at 02:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sourcetree to version 3.4.13 or later on all affected Mac and Windows systems.
  • Restrict or monitor authenticated user access to the application until the upgrade is completed, reducing the window of opportunity for exploitation.
  • Maintain a regular update cadence by reviewing Atlassian release notes and applying any subsequent security patches promptly.

Generated by OpenCVE AI on August 5, 2026 at 02:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Atlassian Sourcetree 3.4.11-12

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title High Severity Remote Code Execution via Authenticated Attack in Sourcetree for Mac and Windows

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title High Severity Remote Code Execution via Authenticated Attack in Sourcetree for Mac and Windows

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Bug Bounty program.
First Time appeared Atlassian
Atlassian sourcetree
CPEs cpe:2.3:a:atlassian:sourcetree:*:*:*:*:*:macos:*:*
cpe:2.3:a:atlassian:sourcetree:3.4.13:*:*:*:*:macos:*:*
Vendors & Products Atlassian
Atlassian sourcetree
References
Metrics cvssV3_0

{'score': 7.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Atlassian Sourcetree
cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2026-07-24T03:55:49.714Z

Reserved: 2026-01-01T00:00:40.720Z

Link: CVE-2026-21575

cve-icon Vulnrichment

Updated: 2026-07-22T18:32:26.447Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')