This weakness occurs across a boundary between an upstream source of input and a downstream interpreter or component. When control-plane syntax is allowed to remain mixed with ordinary data, the downstream component may treat attacker-influenced content as commands, expressions, options, scripts, or other instructions rather than as data. The specific result depends on the downstream component, but the underlying failure is improper neutralization of syntax that has special meaning in that component.