Executive brief
The Guardian language-system, a tool used for automatic translation and subtitling, contains a security flaw in its designer interface. An attacker can send a specially crafted link to a logged-in user that, if clicked, executes malicious scripts in their browser. This could allow the attacker to perform actions on behalf of the user or access sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Guardian language-system within the `src/designer.php` component. The application fails to sanitize the `name` GET parameter before echoing it directly into the `value` attribute of an HTML input tag on line 57. An attacker with low-level authentication (such as a guest account) can craft a malicious URL containing script tags. When a victim visits this URL, the script executes within the context of their browser session, potentially leading to session hijacking or unauthorized actions. The vulnerability affects versions up to and including commit e42c395.
Affected products
- Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory