Disclosure summary
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1.
Source-reported weakness categories
CWE-200, CWE-522
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107399
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-c6rp-p8xm-4q9f
Open original source · Updated Oct 08, 2026
Mechanize sends credential headers to another origin after a meta refresh
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| rubygems | mechanize | < 2.14.1 | 2.14.1 |
Original records & references
PUBLISHED 2026-10-08T18:17:26-04:00
MODIFIED 2026-10-09T12:40:29-04:00
INGESTED 2026-10-10T20:55:03-04:00