The host is installed with Signal Desktop through 1.10.1 and is prone to a cross-site scripting vulnerability. A flaw is present in the application, which fails to handle issues in the resource location. Successful exploitation allows attackers to download/upload files, information or execute arbitrary javascript.