Impact
A cross‑site scripting flaw exists in the Trufflebox UI component GenericNumerixTable.jsx of BharatMLStack. The vulnerability permits an attacker with the ability to inject arbitrary script code into the user interface; when a user views the affected page, the injected code executes in the user’s browser. Such execution can lead to theft of session cookies, credential hijacking, or redirection to malicious sites. The weakness is a client‑side XSS reflected in the generated content of the component.
Affected Systems
BharatMLStack installations incorporating the Trufflebox UI component are vulnerable when running version 1.3.0 or earlier. Any environment that serves GenericNumerixTable.jsx and is accessible to users thus exposes the flaw.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at any given moment. The flaw is not listed in CISA’s KEV catalog, so public exploitation records are not currently known. Based on the description, the likely attack vector is remote, via the web interface; an attacker would need to be able to inject code into the UI, which can then execute in any user’s browser that visits the affected page, compromising confidentiality and integrity of user data.
OpenCVE Enrichment