The explanation for the command injection fix currently reads:
"If an attacker can control part of the strings used to as ..."
It is suggested that 'to' be removed, updating it to:
"If an attacker can control part of the strings used as ..."
Reported by: @davewichers