PT-2026-92168 · Undefined · Undefined

CVE-2026-39039

·

Published

2026-09-15

·

Updated

2026-09-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BharatMLStack versions prior to 1.3.1
Description Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage. This storage mechanism allows any JavaScript running on the page to access these sensitive items, potentially leading to session hijacking or unauthorized access.
Recommendations Update BharatMLStack to a version later than 1.3.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39039

Affected Products

Undefined