There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.
- All versions of SourceTree for Windows before version 184.108.40.206
- Upgrade SourceTree for Windows to version 220.127.116.11 or higher from https://www.sourcetreeapp.com/
Atlassian would like to credit Zhang Tianqi @ Tophant for reporting this issue to us.
For additional details see the full advisory.