Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.Referenceshttps://blog.zulip.com/2020/04/01/zulip-desktop-5-0-0-security-release/