Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
CVE-2026-77115: Brave Popup Builder can run injected scripts from URL links
CVE-2026-77115 · published 12 days ago
Summary
The Brave Popup Builder plugin (versions before 0.8.6) inserts data from URL tracking parameters directly into the popup's code. An attacker could craft a link that makes the popup execute malicious JavaScript in a visitor's browser, potentially stealing information or altering the page. Update to version 0.8.6 or later, or remove the plugin if you cannot upgrade.
What to do
- Update unknown brave to version 0.8.6 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | brave | < 0.8.6 |
Original advisory text
Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
Severity
7.1
High
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published23 Aug 2026
Updated24 Aug 2026
First seen23 Aug 2026
Monitor software like this
Free during beta