Junglewise Threat Intelligence

CVE-2026-39040: BharatMLStack cross-site scripting in Trufflebox UI

CVE-2026-39040 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Executive brief

BharatMLStack is an open-source machine learning infrastructure platform used for managing real-time and batch ML workloads. A cross-site scripting (XSS) vulnerability in the Trufflebox UI component allows attackers to inject malicious scripts that could steal user sessions, compromise data, or deface the interface if a user interacts with a crafted link or embedded content.</exec_brief> <parameter name="technical_details">The vulnerability is a cross-site scripting (XSS) flaw located in the ExpressionViewModal.jsx component of the Trufflebox UI. The vulnerable code fails to properly sanitize or encode user-supplied input before rendering it in the browser, allowing an attacker to inject arbitrary JavaScript. The attack is network-accessible and typically requires user interaction (visiting a malicious link or viewing crafted content). Successful exploitation enables session hijacking, credential theft, or arbitrary actions performed on behalf of the victim user. Versions up to and including 1.3.0 are affected; patches in later releases may be available.</technical_details> <parameter name="affected_products">[{"vendor": "Meesho", "product": "BharatMLStack", "category": "library", "versions": "up to and including 1.3.0"}]

Timeline

  • 2026-09-15: disclosed

References