Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.
Source: NVD ↗ · CISA KEV Catalog ↗