js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
https://twitter.com/lorenzoFB/status/995048605399633926
https://github.com/signalapp/Signal-Desktop/releases/tag/v1.10.1
https://github.com/signalapp/Signal-Desktop/commit/bfbd84f5d1308cdfcb08a1727821f7103be151ea
https://twitter.com/ortegaalfredo/status/995940738839056384
https://twitter.com/bcrypt/status/995057030304952320
Source: Mitre, NVD
Published: 2018-05-14
Updated: 2026-06-17
Base Score: 4.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: Medium
Base Score: 6.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.00336