Junglewise Threat Intelligence

CVE-2026-34117: Guardian language-system OS command injection in text_to_subtitles.php

CVE-2026-34117 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Executive brief

The Guardian language-system, a tool used for automatic translation and subtitling, contains a critical security flaw. An attacker can remotely execute commands on the underlying server without needing a username or password. This could lead to a complete system takeover, theft of sensitive data, or disruption of translation services.

Technical details

An OS command injection vulnerability exists in Guardian language-system due to the improper neutralization of the 'id' GET parameter before it is passed to a PHP exec() call. Specifically, in text_to_subtitles.php at line 19, the application concatenates user-supplied input directly into a shell command string. Because no authentication is required to access this endpoint, a remote, unauthenticated attacker can use shell metacharacters (e.g., semicolons or pipes) to execute arbitrary operating system commands with the privileges of the web server user. The vulnerability affects versions up to and including git commit e42c395.

Affected products

  • Guardian language-system up to commit e42c395ec4b03fe62973a669c9209a673838b8a4

Timeline

  • 2026-07-01: disclosed: Initial disclosure by researcher philopentest
  • 2026-07-01: advisory: NVD and VulnCheck published advisory details

References