Junglewise Threat Intelligence

CVE-2026-34113: Guardian language-system command injection in speech_text.php

CVE-2026-34113 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Executive brief

Guardian language-system, a tool used for automatic translation and subtitling, contains a critical security flaw that allows unauthorized users to take control of the server. By sending a specially crafted web request, an attacker can bypass security controls to run arbitrary commands on the underlying operating system. This could lead to a total compromise of the system, including the theft of sensitive data or the disruption of translation services.

Technical details

An OS command injection vulnerability exists in Guardian language-system due to improper sanitization of the 'id' GET parameter in 'speech_text.php'. At line 18, the application passes this parameter directly into a PHP 'exec()' call used to trigger background jobs. Because no authentication is required to access this endpoint, a remote attacker can inject shell metacharacters (e.g., semicolons or backticks) to execute arbitrary commands with the privileges of the web server user. The vulnerability affects versions up to and including commit e42c395.

Affected products

  • Guardian language-system <= commit e42c395ec4b03fe62973a669c9209a673838b8a4

Timeline

  • 2026-07-01: disclosed: Initial disclosure by researcher philopentest via VulnCheck and GitHub Gist.
  • 2026-07-01: advisory: CVE-2026-34113 published.

References