PT-2026-92168 · Undefined · Undefined
CVE-2026-39039
·
Published
2026-09-15
·
Updated
2026-09-22
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BharatMLStack versions prior to 1.3.1
Description
Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage. This storage mechanism allows any JavaScript running on the page to access these sensitive items, potentially leading to session hijacking or unauthorized access.
Recommendations
Update BharatMLStack to a version later than 1.3.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined