External input alters the structure of a command sent to another system.
Avoid shelling out; use exec-style APIs with argument arrays and strict allowlists.
MITRE ATT&CK techniques associated with this weakness class (mapped via MITRE CAPEC). A vulnerability of this type could let an adversary carry out: