Impact
Guardian Language‑System executes an OS command constructed from an unsanitized GET parameter, enabling an attacker to inject shell metacharacters and run arbitrary commands. This flaw is a classic OS command injection (CWE‑78) that grants full remote code execution, compromising the host’s confidentiality, integrity, and availability.
Affected Systems
All installations of Guardian Language‑System that expose the transcribe_amazon.php endpoint to external HTTP traffic are affected. The vulnerability exists in the source code at line 15, and no specific product version is listed. Any deployment containing that line is vulnerable, irrespective of maintenance status.
Risk and Exploitability
The CVSS base score of 9.3 classifies the issue as critical. The EPSS score of <1% suggests exploitation is not yet widespread, but the problem can be triggered with a simple GET request and requires no authentication, making the attack vector trivial for anyone with network access to the web server. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment