Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
https://www.debian.org/security/2022/dsa-5075
https://github.com/minetest/minetest/security/advisories/GHSA-hwj2-xf72-r4cf
https://github.com/minetest/minetest/commit/b5956bde259faa240a81060ff4e598e25ad52dae