Improper input validation enabling arbitrary Gstreamer pipeline injection. (CVE-2023-6185) Link targets allow arbitrary script execution. (CVE-2023-6186)