Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10 V contain certain field types that do not properly sanitize data from non-form sources, which can lead to arbitrary PHP code execution in some cases.
View the template here CVE-2019-6340.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2019-6340