"The product uses a function that accepts a format string as an argument, but the format string originates from an external source." - Entry from the Common Weakness Enumeration
For more info visit <a href="https://cwe.mitre.org/data/definitions/134.html" target="_blank" rel="noopener noreferrer">CWE-134</a>