A cron expression with both a day-of-month and a day-of-week field set to anything other than a wildcard almost never means what it looks like it means. The schedule 0 9 1 * MON, written to mean "9am on the 1st, if it's a Monday", actually runs on the 1st of every month regardless of weekday, and separately on every Monday. Those two fields are combined with an implicit OR, not an AND, and this single rule accounts for the large majority of cron jobs that run more often than their author intended.
The behaviour is specified, not a bug, and it dates back to the original cron implementation rather than being an inconsistency introduced by a particular scheduler. Most modern cron-compatible tools preserve it for compatibility, which means the trap persists even in schedulers written decades after the original. The exception that catches people out in the other direction: if either field is left as a wildcard, the OR rule stops mattering, because a wildcard matches everything and the other field alone determines the schedule.
The practical fix depends on what you actually meant. If you wanted "the 1st of the month, whatever day that falls on", leave day-of-week as a wildcard and use only day-of-month. If you wanted "every Monday", leave day-of-month as a wildcard and use only day-of-week. If you genuinely need "the first Monday of the month", cron's five fields cannot express that directly — most schedulers need either a wrapper script that checks the date, or a day-of-week value combined with external logic, since no standard cron field combination means "first occurrence of this weekday in the month".
A fast way to catch this before it ships: whenever a schedule uses both a specific day-of-month and a specific day-of-week in the same expression, treat that as a signal to pause and check what it actually produces, because the combination is unintuitive by specification rather than by accident. A tool that previews the next several run dates for a given expression settles the question immediately, which is more reliable than reasoning through the OR rule by hand under time pressure.