{"id":"CVE-2026-107399","title":"The Mechanize library is used for automating interaction with websites","summary":"The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A p…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-200","CWE-522"],"vendor":"mechanize","product":"mechanize","affected":["mechanize < 2.14.1"],"patched":["mechanize 2.14.1"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:26.683","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107399","references":[{"url":"https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f","label":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/commit/84c74df87d15f5d119df268ba6aa79bc1e16a2c3","label":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/pull/676","label":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1","label":"security-advisories@github.com"},{"url":"https://github.com/sparklemotion/mechanize/security/advisories/GHSA-c6rp-p8xm-4q9f","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-c6rp-p8xm-4q9f"}],"tags":["nvd","ghsa","rubygems"],"aliases":["GHSA-c6rp-p8xm-4q9f"],"ecosystem":"rubygems","ingestedAt":"2026-10-08T22:11:53.871Z","slug":"CVE-2026-107399","body":"## Overview\n\nThe Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107399)\n\nAffected packages:\n\n- `mechanize < 2.14.1`\n\nPatched in:\n\n- `mechanize 2.14.1`\n\nSource: https://github.com/advisories/GHSA-c6rp-p8xm-4q9f","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}