In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
{ "urgency": "not yet assigned" }
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-39331.json"