PT-2026-108213 · Rubygems · Mechanize

CVE-2026-107399

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mechanize versions prior to 2.14.1
Description When Mechanize#follow meta refresh is enabled, the library fails to apply an origin trust boundary in the Mechanize::HTTP::Agent#response follow meta refresh function. This allows headers configured via Mechanize#request headers= to be reapplied to requests following a meta refresh to a different origin. An attacker capable of placing a meta refresh in a page fetched by the agent can capture sensitive information such as bearer tokens or session cookies.
Recommendations Update to version 2.14.1. As a temporary workaround, keep Mechanize#follow meta refresh set to its default value of false or avoid using Mechanize#request headers= for credentials when meta refresh following is enabled.

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107399
GHSA-C6RP-P8XM-4Q9F

Affected Products

Mechanize