There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
- All versions of SourceTree for Windows before version 22.214.171.124
- Upgrade SourceTree for Windows to version 126.96.36.199 or higher from https://www.sourcetreeapp.com/
Atlassian would like to credit Zhang Tianqi @ Tophant for reporting this issue to us.
For additional details see the full advisory.