PT-2026-108213 · Rubygems · Mechanize
CVE-2026-107399
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mechanize versions prior to 2.14.1
Description
When
Mechanize#follow meta refresh is enabled, the library fails to apply an origin trust boundary in the Mechanize::HTTP::Agent#response follow meta refresh function. This allows headers configured via Mechanize#request headers= to be reapplied to requests following a meta refresh to a different origin. An attacker capable of placing a meta refresh in a page fetched by the agent can capture sensitive information such as bearer tokens or session cookies.Recommendations
Update to version 2.14.1.
As a temporary workaround, keep
Mechanize#follow meta refresh set to its default value of false or avoid using Mechanize#request headers= for credentials when meta refresh following is enabled.Fix
Information Disclosure
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mechanize