Junglewise Threat Intelligence

CVE-2026-34115: Guardian language-system OS command injection in transcribe_amazon.php

CVE-2026-34115 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Executive brief

The Guardian language-system, a tool used for automatic translation and subtitling, contains a critical security flaw. An attacker can remotely take control of the server by sending a specially crafted web request. This could lead to the theft of sensitive data, disruption of services, or full system compromise without requiring any login credentials.

Technical details

An OS command injection vulnerability exists in the Guardian language-system due to the improper neutralization of special elements in the 'id' GET parameter. In 'transcribe_amazon.php' (line 15), the application passes this parameter directly into a PHP exec() call without sanitization. A remote, unauthenticated attacker can exploit this by appending shell metacharacters to the 'id' parameter, leading to arbitrary command execution with the privileges of the web server user. The vulnerability affects versions up to and including git commit e42c395.

Affected products

  • Guardian language-system <= commit e42c395ec4b03fe62973a669c9209a673838b8a4

Timeline

  • 2026-07-01: disclosed: Initial disclosure by VulnCheck and researcher philopentest.
  • 2026-07-01: advisory: CVE-2026-34115 published.

References