That is an excellent question!! It's very hard to find details anywhere...
The
Kodi page for the latest update says this, which suggests that the subtitlte text file itself is not the culprit:
To be clear this possible vunrability is only present when you first enable a subtitle dowload add-on and then actually download zipped subtitles. Any subtitles that you already have as text file, are embedded in the video stream or are included with you DVD or Blurays are safe.
That sounds like the security vulnerability was in the automatic downloading and unpacking of zipped subtitle files by media players.
But I'd really like some confirmation about that.
Another media player change log sheds a little bit of light, but not much:
https://ci.popcornti...rn-Time-Desktop/249/