CVE-2026-39040
BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.
- Published Sep 15, 2026
- CVSS 5.4 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)