CVE-2018-1000006 is a perfect example of why using the Web for desktop apps is a hilariously bad idea.
"Electron [...] can be tricked in arbitrary command execution if the user clicks on a specially crafted URL." :hyperlul:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000006