Executive brief
The Guardian language-system, a tool used for automatic translation and subtitle rendering, contains a critical security flaw. An attacker can exploit this to take complete control of the server by sending a specially crafted web request. This could lead to the theft of sensitive data, disruption of translation services, or the use of the server for further attacks, all without needing a username or password.
Technical details
An OS command injection vulnerability exists in the Guardian language-system due to the unsafe use of the PHP exec() function within 'subtitles.php'. The application takes the 'id' GET parameter and concatenates it directly into a shell command string without any sanitization or validation. Because this specific endpoint does not require authentication, a remote attacker can use shell metacharacters (e.g., semicolons or pipes) within the 'id' parameter to execute arbitrary commands with the privileges of the web server user. This vulnerability affects versions up to and including commit e42c395.
Affected products
- Guardian language-system <= commit e42c395ec4b03fe62973a669c9209a673838b8a4
Timeline
- 2026-07-01: disclosed: Vulnerability details and PoC published by researcher philopentest via GitHub Gist.
- 2026-07-01: advisory: CVE-2026-34106 published.