Executive brief
The Guardian language-system, a tool used for automated translation and subtitling, contains a critical security flaw. An attacker can remotely take control of the server by sending a specially crafted web request. This could lead to a total compromise of the system, including the theft of sensitive data or the disruption of media processing operations.
Technical details
An OS command injection vulnerability exists in Guardian language-system due to improper neutralization of special elements in the 'id' GET parameter. In speechmac.php (line 18), the application passes the unsanitized 'id' parameter directly into a PHP exec() call. A remote, unauthenticated attacker can exploit this by appending shell metacharacters to the parameter, leading to arbitrary command execution with the privileges of the web server user. This vulnerability affects versions up to and including commit e42c395.
Affected products
- Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4
Timeline
- 2026-07-01: disclosed: Vulnerability details and PoC published by researcher philopentest.
- 2026-07-01: advisory: NVD and VulnCheck published advisory details.