Improper access control in Sourcetree for Windows and Sourcetree for macOS - CVE-2026-21575

 

Improper access control in Sourcetree for Windows and Sourcetree for macOS - CVE-2026-21575

Published: July 22, 2026 / Updated: July 22, 2026


Vulnerability identifier: #VU139072
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21575
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper access control in Sourcetree for Windows when handling crafted content. A remote attacker can trick the victim into processing crafted content to execute arbitrary code.

User interaction is required for exploitation.


Affected software

Sourcetree for Windows
Sourcetree for macOS

How to mitigate CVE-2026-21575

Install security update from vendor's website.

Sourcetree for Windows - update to 3.4.13
Sourcetree for macOS - update to 3.4.13

External References

Related Security Bulletins