Insecure deserialization of untrusted data leading to remote code execution.
MITRE. (n.d.). Common Weakness Enumeration (CWE).