Skip to content
archivevulnerability · 09 Sep 2026 · 23:48 UTC

GHSA-m835-3cm9-rggg: Joker linter executed project-local .jokerd/linter.* files during linting

VULNCVE-2026-59172source · GTH
HIGHHigh-risk vulnerability — CVSS 7.8

last 60 dispatches · spectrum

## Impact In Joker versions before 1.8.2, `joker --lint ` located a `.jokerd/` directory by walking up from the linted file and executed matching `linter.*` files from that directory before linting. Because these files are executable Joker/Clojure code, linting a file inside an untrusted repository could execute code supplied by that repository. This could be triggered by editor integrations or CI jobs that automatically run `joker --lint` on checked-out source code. ## Patches Fixed in Joker v1.8.2. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected