logo

Technical Advisory: Shell Injection in SourceTree

ID: 35c0a1f2-5006-5f65-b91e-74f55c38fd76

STIX ID: report--35c0a1f2-5006-5f65-b91e-74f55c38fd76

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

NCC Group disclosed a critical shell injection vulnerability in Atlassian SourceTree's `sourcetree://` URL handler affecting SourceTree v1.9.8 and earlier; an attacker can achieve remote code execution by tricking a user into opening a crafted `sourcetree://` link (including via a browser META refresh). The advisory includes technical details, a proof-of-concept vector, vendor coordination notes, and recommends upgrading to a non-vulnerable SourceTree release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.