Use of Externally-Controlled Format String
CWE-134 · Base · Draft
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.