Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Tracking upstream https://github.com/daxelrod/jowl/pull/60 , will likely be able to release next week both upstream and in Fedora. As Jowl is primarily a tool for users to run their own arbitrary code, I have trouble thinking of a threat model in which this is unknowingly exploitable.