What happened
An attacker sends a malicious metadata filter key to the get_state_history() endpoint, injecting SQL that causes the checkpointer to return an attacker-crafted checkpoint row containing malicious serialized data, which is then deserialized and executed by the server.