A remote code execution bug was found on OSX when using terminal-notifier for desktop notifications:
https://github.com/boothj5/profanity/issues/507To avoid this issue, make sure the following settings are disabled:
/notify message text off
/notify room text off
/notify invite off
Other operating systems are unaffected.
A fix has been added, and will be in 0.4.6.