CVE-2026-21575
Received Received - Intake

Remote Code Execution in Sourcetree for Mac and Windows

Vulnerability report for CVE-2026-21575, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-21

Assigner: Atlassian

Description

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Bug Bounty program.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-21
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
atlassian sourcetree From 3.4.13 (inc)
atlassian confluence From 10.2.0 (inc) to 10.2.13 (inc)
atlassian confluence From 10.1.0 (inc) to 10.1.2 (inc)
atlassian confluence From 10.0.2 (inc) to 10.0.3 (inc)
atlassian confluence to 10.2.0 (exc)
atlassian confluence to 9.2.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a high-severity Remote Code Execution (RCE) vulnerability affecting Sourcetree for Mac and Windows versions 3.4.11 and earlier. It allows an authenticated attacker to execute arbitrary code on a victim's system with high impacts to confidentiality, integrity, and availability. The vulnerability requires user interaction to exploit.

Detection Guidance

This vulnerability affects Sourcetree for Mac and Windows versions 3.4.11. Detection involves checking installed Sourcetree versions. Use commands like 'sourcetree --version' on Mac or check the installation directory on Windows. Compare the version against 3.4.13 or later.

Impact Analysis

An attacker could exploit this to run malicious code on your system, potentially stealing data, installing malware, or disrupting operations. Since it requires user interaction, victims must be tricked into triggering the exploit, such as opening a malicious file or link.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with standards like GDPR or HIPAA. However, the described RCE vulnerability could potentially lead to unauthorized access to sensitive data, which may affect compliance if such data is involved.

Mitigation Strategies

Upgrade Sourcetree for Mac and Windows to version 3.4.13 or later. If unable to upgrade, apply the latest supported fixed version as recommended by Atlassian.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21575. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart