CVE-2026-39039

Status: Received

Description

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

Published
September 15, 2026 6:17 PM
Last Modified
September 15, 2026 6:17 PM
Source
[email protected]

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.