Product
Joker versions before 1.8.2 are vulnerable to arbitrary code execution because the linter automatically traverses directory structures to execute project-local 'linter.*' files, allowing execution of attacker-supplied code within untrusted repositories.