CVE-2026-77115: Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters
Published Aug 23, 2026
·Updated
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
Affected Software
2 affected components
brave-popup-builder<=0.8.5
brave-popup-builder<0.8.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
brave-popup-builderto a version that resolves this vulnerability.Fixed in 0.8.6
Event History
Aug 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to get a victim to visit a URL containing crafted UTM query parameters. No authentication is required to trigger the reflected script injection.
2
Which installations are affected?
Brave Popup Builder versions up to and including 0.8.5 are affected. The issue occurs when UTM query parameters are reflected into popup form HTML without escaping.