Executive brief
The Guardian language-system, a tool used for automatic translation and subtitling, contains a security flaw in how it handles job information requests. An attacker can exploit this to gain unauthorized access to the underlying database, potentially exposing sensitive configuration data or internal records. This could lead to a full compromise of the system's data integrity and confidentiality.
Technical details
A SQL injection vulnerability exists in the Guardian language-system due to improper sanitization of the 'id' GET parameter in the job_info_get.php script. The application passes the user-supplied input directly into a SQL query string on line 16. Although some descriptions suggest authentication is required, the underlying proof-of-concept and CVSS metrics indicate the endpoint is reachable without authentication. An attacker can use error-based SQL injection techniques (such as using GTID_SUBSET) to extract sensitive information, including database versions, user accounts, and table contents. The vulnerability affects all versions up to and including git commit e42c395.
Affected products
- Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4
Timeline
- 2026-07-01: disclosed: Researcher disclosure by philopentest via GitHub Gist
- 2026-07-01: advisory: NVD and VulnCheck published advisory details