- 
    Bug 
- 
    Resolution: Fixed
- 
    Highest 
- 
    0.8.4b
- 
    None
- 
        Severity 1 - Critical
SourceTree for Windows is affected by a command injection vulnerability in URI handling. The vulnerability can be triggered through a browser or the SourceTree interface.
Affected versions:
- Versions of SourceTree for Windows starting with 0.8.4b before version 2.0.20.1 are affected by this vulnerability.
Fix:
- Upgrade SourceTree for Windows to version 2.0.20.1 or higher from https://www.sourcetreeapp.com/
Acknowledgements
 We would like to credit Yu Hong for reporting this issue to us.
For additional details see the full advisory.