CVE-2026-107399 — The Mechanize library is used for automating interaction with websites.
Description
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Changed
Scope
C
High
Confidentiality
I
None
Integrity
A
None
Availability
References
- advisory[email protected]https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f
- advisory[email protected]https://github.com/sparklemotion/mechanize/commit/84c74df87d15f5d119df268ba6aa79bc1e16a2c3
- advisory[email protected]https://github.com/sparklemotion/mechanize/pull/676
- advisory[email protected]https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1
- advisory[email protected]https://github.com/sparklemotion/mechanize/security/advisories/GHSA-c6rp-p8xm-4q9f
Related threats
same CWE or vendorCVE-2026-107715 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107715 · 2h ago
CVE-2026-107714 — The Mechanize library is used for automating interaction with websites.
CVE-2026-107714 · 2h ago
CVE-2026-84274 — IBM Guardium Data Protection 12.2.2 is affected by a sensitive information exposure vulnerability.
CVE-2026-84274 · 4h ago
CVE-2026-107383 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.
CVE-2026-107383 · 5h ago
CVE-2026-105452 — Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy.
CVE-2026-105452 · 5h ago
PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-61431 · 6h ago