Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.1

CVE-2026-77115: Brave Popup Builder can run injected scripts from URL links

CVE-2026-77115 · published 12 days ago
Summary

The Brave Popup Builder plugin (versions before 0.8.6) inserts data from URL tracking parameters directly into the popup's code. An attacker could craft a link that makes the popup execute malicious JavaScript in a visitor's browser, potentially stealing information or altering the page. Update to version 0.8.6 or later, or remove the plugin if you cannot upgrade.

What to do
  • Update unknown brave to version 0.8.6 or later.
Affected software
VendorProductAffected versions
unknown brave < 0.8.6
Original advisory text
Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
Severity
7.1 High
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published23 Aug 2026
Updated24 Aug 2026
First seen23 Aug 2026
Sources
CVE-2026-77115 · MITRE
Monitor software like this
Free during beta