CVE-2026-39038

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

Published 2026-09-15. Last modified 2026-09-22.