CVE-2026-39040
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.
Published 2026-09-15. Last modified 2026-09-22.