Junglewise Threat Intelligence

CVE-2026-34098: Guardian language-system XSS in media.php id parameter

CVE-2026-34098 · Severity: medium · CVSS 4.6 · Published 2026-07-01

Executive brief

The Guardian language-system, a tool used for automatic translation and subtitling, contains a security flaw that allows for cross-site scripting (XSS). An attacker with basic user access can send a specially crafted link to another user; if clicked, the attacker can execute malicious scripts in the victim's browser. This could lead to the theft of session cookies, unauthorized actions on behalf of the user, or the defacement of the application interface.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the Guardian language-system within the 'media.php' component. The application fails to sanitize or encode the 'id' GET parameter before echoing it into the HTML source (line 119) and the 'action' attribute of a form (line 129). An authenticated attacker can exploit this by crafting a malicious URL containing a JavaScript payload and tricking a victim into visiting it. Successful exploitation allows the execution of arbitrary script code in the context of the victim's browser session. The vulnerability affects versions up to and including git commit e42c395.

Affected products

  • Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4

Timeline

  • 2026-07-01: disclosed: Initial disclosure via VulnCheck and researcher PoC
  • 2026-07-01: advisory: CVE-2026-34098 published

References