# CVE-2026-39039

## Summary

- **CVE ID:** CVE-2026-39039
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 16, 2026

## Description

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](https://github.com/Meesho/BharatMLStack)
- [CNA](https://github.com/wincr4ck/security-advisories/blob/main/bharatmlstack-cve-writeup.md)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 8.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._