CVE-2012-4463: Midnight-Commander Midnight Commander

Medium severity, CVSS 5.1. EPSS: 1.9% chance of exploitation in the next 30 days.

Midnight Commander (mc) 4.8.5 does not properly handle the (1) MC_EXT_SELECTED or (2) MC_EXT_ONLYTAGGED environment variables when multiple files are selected, which allows user-assisted remote attackers to execute arbitrary commands via a crafted file name.

Affected products

Published 2012-10-10. Last modified 2026-06-16.