External input becomes part of an OS command executed by the product.
Never interpolate input into shell strings; pass argument vectors and validate against allowlists.
MITRE ATT&CK techniques associated with this weakness class (mapped via MITRE CAPEC). A vulnerability of this type could let an adversary carry out: