Junglewise Threat Intelligence

CVE-2026-34114: Guardian language-system OS command injection in translate_text.php

CVE-2026-34114 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Executive brief

The Guardian language-system, a tool used for automatic translation and subtitling, contains a critical security flaw. An attacker can remotely execute malicious commands on the server without needing a username or password. This could lead to a complete takeover of the system, theft of sensitive data, or disruption of translation services.

Technical details

A command injection vulnerability exists in Guardian language-system within the 'translate_text.php' component. The application takes the 'id' GET parameter and passes it directly into a PHP exec() call at line 18 without any sanitization or validation. Because this endpoint does not require authentication, a remote attacker can append shell metacharacters (e.g., semicolons or pipes) to the 'id' parameter to execute arbitrary operating system commands with the privileges of the web server user. The vulnerability is present in versions up to and including git commit e42c395.

Affected products

  • Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4

Timeline

  • 2026-07-01: disclosed: Vulnerability details and PoC published by researcher philopentest via GitHub Gist.
  • 2026-07-01: advisory: CVE-2026-34114 published.

References