Atlassian Sourcetree vulnerabilities
15 known vulnerabilities affecting atlassian/sourcetree.
Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH12MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-22165MEDIUMCVSS 5.9≥ 4.2.8, ≤ 4.2.122025-07-24
CVE-2025-22165 [MEDIUM] CWE-269 CVE-2025-22165: This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of
This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac.
This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to ava
nvd
CVE-2024-21697HIGHCVSS 8.8v3.4.19v4.2.82024-11-19
CVE-2024-21697 [HIGH] CVE-2024-21697: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sou
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, hi
nvd
CVE-2023-22514HIGHCVSS 7.8≥ 3.4.0, < 3.4.15≥ 4.1.0, < 4.2.52024-01-16
CVE-2023-22514 [HIGH] CWE-94 CVE-2023-22514: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sou
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows.
This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H which allows an unauthenticated attacker to execute arbitrary code w
nvd
CVE-2019-11582HIGHCVSS 8.8≥ 0.5a, < 3.1.32019-06-14
CVE-2019-11582 [HIGH] CWE-88 CVE-2019-11582: An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versi
An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.
nvd
CVE-2018-20236HIGHCVSS 8.8≥ 0.5a, < 3.0.102019-03-08
CVE-2018-20236 [HIGH] CWE-77 CVE-2018-20236: There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before vers
There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system.
nvd
CVE-2018-20235HIGHCVSS 8.8≥ 0.5a, < 3.0.152019-03-08
CVE-2018-20235 [HIGH] CVE-2018-20235: There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a
There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
nvd
CVE-2018-20234HIGHCVSS 8.8≥ 1.2.0, < 3.1.12019-03-08
CVE-2018-20234 [HIGH] CWE-88 CVE-2018-20234: There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 bef
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
nvd
CVE-2018-13396HIGHCVSS 8.8≥ 1.0, < 3.0.0v1.02018-11-05
CVE-2018-13396 [HIGH] CVE-2018-13396: There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before vers
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.
nvd
CVE-2018-13397HIGHCVSS 8.8≥ 0.5.1.0, < 3.0.02018-11-05
CVE-2018-13397 [HIGH] CVE-2018-13397: There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before
There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
nvd
CVE-2018-13385CRITICALCVSS 9.8≥ 1.0, < 2.7.6v1.02018-07-24
CVE-2018-13385 [CRITICAL] CWE-88 CVE-2018-13385: There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial rep
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for macOS from 1.0b2 before 2.7.6 are affected by thi
nvd
CVE-2018-13386HIGHCVSS 8.1fixed in 2.6.92018-07-24
CVE-2018-13386 [HIGH] CWE-88 CVE-2018-13386: There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial r
There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. Versions of Sourcetree for Windows before version 2.6.9 are affected by this
nvd
CVE-2018-5226HIGHCVSS 8.8fixed in 2.5.5.02018-04-25
CVE-2018-5226 [HIGH] CVE-2018-5226: There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag
There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. All versions of Sourcetree for Windows before 2.5.5.0 are
nvd
CVE-2017-14593HIGHCVSS 8.8≥ 0.5.1.0, < 2.4.7.02018-01-26
CVE-2017-14593 [HIGH] CWE-77 CVE-2017-14593: Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git reposito
Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. From version 0.8.4b of Sourcetree for Windows, this vulnerability can be triggered fro
nvd
CVE-2017-14592HIGHCVSS 8.8≥ 1.0, < 2.7v1.02018-01-26
CVE-2017-14592 [HIGH] CWE-77 CVE-2017-14592: Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system. From version 1.4.0 of Sourcetree for macOS, this vulnerability can be triggered from a web
nvd
CVE-2017-8768CRITICALCVSS 9.8≤ 2.5c2017-05-04
CVE-2017-8768 [CRITICAL] CWE-78 CVE-2017-8768: Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sour
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS command execution with a URL substring of sourcetree://cloneRepo/ext:: or sourcetree://checkoutRef/ext:: followed by the command. The Atlassian ID number is SRCTREE-4632.
nvd