The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2016-5118.json"