Regarding the command injection issue.


I am new to sourcetree, I was checking it before installing it and I read about the command injection issue. I've also checked the question in this link:

I would like to know if this: SourceTreeSetup-

is the latest and has the issue solved?

2 answers

This widget could not be displayed.

Hi! Yes, SourceTree is the latest one for Windows and it's not affected by the injection issue, it was fixed :)

Let us know if you need anything else!



This widget could not be displayed.

Thanks for your reply, I am really glad to hear.

I have one last question though:

according to:

the version effected was 2.5c and prior, the one in SourceTree offical site is This is confusing since 2.0 is prior to 2.5?

Thanks in advance,

Hi! For official information regarding the vulnerability, my recommendation is that you check our official source. You can find it at SourceTree Security Advisory.

Note that the site you linked is not even differentiating between Mac and Windows versions. Whilst this is not mentioned in that website, they're probably referring to the Mac version of SourceTree (which is currently 2.5.2).

Hope this clears your concerns :)


Yes, Thank you very much! =)

Suggest an answer

Log in or Sign up to answer
Community showcase
Published May 30, 2018 in Sourcetree

Tip from the team: configuring Git or Mercurial in Sourcetree

Supported Platforms macOS Windows To make using Sourcetree as simple yet powerful as possible we embed (bundle) dependencies such as Git, Git LFS, and Mercurial. We strive to keep these...

874 views 2 3
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you