{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acandid82joker/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:candid82:joker:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Joker (\u003c 1.8.2)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","development-tools"],"_cs_type":"advisory","_cs_vendors":["Candid82"],"content_html":"\u003cp\u003eJoker versions before 1.8.2 are vulnerable to arbitrary code execution (CVE-2026-59172) due to insecure handling of linter configuration files. When the \u003ccode\u003ejoker --lint\u003c/code\u003e command is executed, the application performs a directory traversal, walking up the file system from the target file to locate a \u003ccode\u003e.jokerd/\u003c/code\u003e directory. If found, the linter automatically executes any matching \u003ccode\u003elinter.*\u003c/code\u003e files (e.g., \u003ccode\u003elinter.clj\u003c/code\u003e, \u003ccode\u003elinter.cljs\u003c/code\u003e) located within that directory. Because these files contain executable Joker or Clojure code, an attacker can place malicious scripts inside a \u003ccode\u003e.jokerd/\u003c/code\u003e directory within a repository. If a user or automated CI/CD pipeline runs the Joker linter against files in the compromised repository, the linter will execute the attacker's code with the privileges of the user running the process. This is particularly dangerous for developers using IDE integrations that automatically trigger linters on opened or saved files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target repository or project that utilizes the Joker linter for code quality checks.\u003c/li\u003e\n\u003cli\u003eAttacker creates a hidden directory named \u003ccode\u003e.jokerd/\u003c/code\u003e in the root of the repository or a subdirectory.\u003c/li\u003e\n\u003cli\u003eAttacker writes a malicious script into a file such as \u003ccode\u003elinter.clj\u003c/code\u003e within the \u003ccode\u003e.jokerd/\u003c/code\u003e folder.\u003c/li\u003e\n\u003cli\u003eAttacker submits a pull request, clones the repository, or lures a victim into opening the repository in an editor.\u003c/li\u003e\n\u003cli\u003eThe victim or an automated CI/CD server triggers \u003ccode\u003ejoker --lint \u0026lt;target_file\u0026gt;\u003c/code\u003e on the repository.\u003c/li\u003e\n\u003cli\u003eThe Joker binary traverses the directory structure, identifies the malicious \u003ccode\u003e.jokerd/linter.clj\u003c/code\u003e file, and loads it into the interpreter.\u003c/li\u003e\n\u003cli\u003eThe malicious code executes, resulting in unauthorized command execution under the context of the user or CI service account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on the host machine running the Joker linter. This impacts developers, build servers, and automated linting environments. Attackers can leverage this to gain initial access to development environments, exfiltrate environment variables, compromise CI pipelines, or move laterally within a development infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Joker to version 1.8.2 or later immediately to restrict linter configuration loading to the user-specific \u003ccode\u003e~/.jokerd/\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003eImplement a policy in CI/CD environments to audit or block repositories containing \u003ccode\u003e.jokerd/\u003c/code\u003e directories if they are not explicitly managed by the organization.\u003c/li\u003e\n\u003cli\u003eDeploy detection rules to identify command-line executions of \u003ccode\u003ejoker --lint\u003c/code\u003e that coincide with unexpected file system access to \u003ccode\u003e.jokerd\u003c/code\u003e subdirectories in application project paths.\u003c/li\u003e\n\u003cli\u003ePrioritize patching CVE-2026-59172 on all build servers and developer workstations where Joker is utilized.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T00:51:19Z","date_published":"2026-09-10T00:51:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-joker-linter-rce/","summary":"Joker versions before 1.8.2 are vulnerable to arbitrary code execution because the linter automatically traverses directory structures to execute project-local 'linter.*' files, allowing execution of attacker-supplied code within untrusted repositories.","title":"Arbitrary Code Execution in Joker Linter via Malicious Project-Local Configuration","url":"https://feed.craftedsignal.io/briefs/2026-09-joker-linter-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:candid82:joker:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}