A link can point to a website. A website can contain malicious code. Google for all the malware currently running around on the Internet for examples of exactly what is possible just by going to a website. It is really easy to do because a website can run client side code.
This is the same problem that email clients (and anything else that renders HTML) have and why one of the things they always teach in security training at every company you'll probably ever work at is that you never, ever click a link unless you are sure that you trust that link.