Junglewise Threat Intelligence

CVE-2026-34097: Guardian language-system reflected XSS in text_file.php

CVE-2026-34097 · Severity: medium · CVSS 4.6 · Published 2026-07-01

Executive brief

The Guardian language-system, a tool used for automatic translation and subtitling, contains a security flaw in how it handles web addresses. An attacker can create a malicious link that, if clicked by a logged-in user, allows the attacker to run unauthorized scripts in that user's browser. This could lead to the theft of session information or unauthorized actions being performed on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Guardian language-system within the 'text_file.php' component. The application fails to sanitize the 'id' GET parameter before echoing it into the 'action' attribute of multiple HTML forms (specifically at lines 94, 101, 323, 403, 826, and 852). An authenticated attacker can exploit this by crafting a URL containing a malicious payload that breaks out of the attribute context to inject script tags. The vulnerability requires the victim to be logged in and interact with the malicious link. The issue affects versions up to and including git commit e42c395.

Affected products

  • Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4

Timeline

  • 2026-07-01: disclosed: Initial researcher disclosure via GitHub Gist and VulnCheck advisory.
  • 2026-07-01: advisory: CVE-2026-34097 published.

References