I don't know if this is exploitable, but they are using many different methods to escape HTML content:
https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1...
Then here it's a different function:
https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1...
Then sometimes they use the underscore library to do it:
https://github.com/signalapp/Signal-Desktop/blob/d1f7f5ee8c1...
Which their implementation seems to be using regular expressions as well.