The risk, to be brief, is that a CLA provides one community member, usually a founding member that is a corporation, privileges that other members do not have.
It gives them the power to do a rug-pull and take future development of the software out of the open source world, as we have seen with e.g. MongoDB, Redis and HashiCorp's products.