Junglewise Threat Intelligence

CVE-2026-21575: Atlassian Sourcetree remote code execution

CVE-2026-21575 · Severity: high · CVSS 7.1 · Published 2026-07-21

Vendors: Atlassian.

Executive brief

Atlassian Sourcetree, a popular desktop application for managing Git repositories, is affected by a security flaw that could allow an attacker to take control of a user's computer. By tricking a logged-in user into performing a specific action, an attacker could execute malicious commands, potentially leading to data theft or full system compromise. Users are advised to update to version 3.4.13 or later to resolve this issue.

Technical details

A Remote Code Execution (RCE) vulnerability exists in Atlassian Sourcetree for Mac and Windows versions 3.4.11 and 3.4.12. The flaw allows an authenticated attacker to execute arbitrary code on the host system, though the attack requires high complexity and specific user interaction (UI:R). The vulnerability was identified through Atlassian's Bug Bounty program and carries a CVSS score of 7.1. The issue is resolved in Sourcetree version 3.4.13 and all subsequent releases.

Affected products

  • Atlassian Sourcetree for Mac 3.4.11 to 3.4.12
  • Atlassian Sourcetree for Windows 3.4.11 to 3.4.12

Timeline

  • 2026-07-07: disclosed: Vulnerability reported via Bug Bounty program
  • 2026-07-21: advisory: Official Atlassian security bulletin published
  • 2026-07-21: patched: Fixed in version 3.4.13

References