In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | BharatMLStack Trufflebox UI Exposes JWT Tokens via LocalStorage | |
| Weaknesses | CWE-200 CWE-312 |
Tue, 15 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-15T17:29:58.654Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-39039
No data.
Status : Received
Published: 2026-09-15T18:17:20.657
Modified: 2026-09-15T18:17:20.657
Link: CVE-2026-39039
No data.
OpenCVE Enrichment
Updated: 2026-09-16T08:45:19Z