Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules.bin\wmic.exe file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19954.json"