ReviewHigh
CVE-2026-77115
Brave
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
- CVSS
- 7.1
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.23
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
The CVSS severity warrants an early asset and exposure review.
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
Confirm exposure before applying a vendor-supported change.
Confirm that Brave and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.