CVE-2026-39038: XSS
Published Sep 15, 2026
·Updated
BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.
Affected Software
1 affected component
BharatMLStack BharatMLStack<=v1.3.0
Event History
Sep 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are affected?
BharatMLStack versions up to and including 1.3.0 are affected where the Trufflebox UI component is present. The issue is located in trufflebox-ui's GenericNumerixTable.jsx.
2
What vulnerability class should defenders investigate?
This is a cross-site scripting vulnerability. Review how GenericNumerixTable.jsx handles data rendered in the Trufflebox UI for paths that could allow script content to execute in a user's browser.