In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
https://www.openwall.com/lists/oss-security/2024/06/23/2
https://www.openwall.com/lists/oss-security/2024/06/23/1
https://news.ycombinator.com/item?id=40768225
https://lists.gnu.org/archive/html/info-gnu-emacs/2024-06/msg00000.html
https://lists.debian.org/debian-lts-announce/2024/06/msg00024.html
https://lists.debian.org/debian-lts-announce/2024/06/msg00023.html
https://list.orgmode.org/87sex5gdqc.fsf%40localhost/
https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29