Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.23
EPSS Ranking 95.6%