CVE-2018-14354: mutt: Remote code injection vulnerability to an IMAP mailbox

Severity: Critical

CVSS Score: 9.8

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.