← back
CVE-2026-77115highCWE-79

Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1
exploitation probability
observed exploitation
nono source reports it
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Affected products
Unknown · Brave