Critical severity9.8NVD Advisory· Published Jul 1, 2026· Updated Jul 14, 2026
CVE-2026-34106
CVE-2026-34106
Description
Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to the id parameter to execute arbitrary OS commands on the server.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.