osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.