{"id":"CVE-2026-107399","summary":"Mechanize sends credential headers to another origin after a meta refresh","details":"The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1.","aliases":["GHSA-c6rp-p8xm-4q9f"],"modified":"2026-10-11T02:30:52.180698733Z","published":"2026-10-08T21:24:46.349Z","database_specific":{"cwe_ids":["CWE-200","CWE-522"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107399.json","unresolved_ranges":[{"extracted_events":[{"fixed":"2.15.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107399.json"},{"type":"ADVISORY","url":"https://github.com/sparklemotion/mechanize/security/advisories/GHSA-c6rp-p8xm-4q9f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107399"},{"type":"FIX","url":"https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f"},{"type":"FIX","url":"https://github.com/sparklemotion/mechanize/commit/84c74df87d15f5d119df268ba6aa79bc1e16a2c3"},{"type":"FIX","url":"https://github.com/sparklemotion/mechanize/pull/676"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sparklemotion/mechanize","events":[{"introduced":"0"},{"fixed":"02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f"},{"fixed":"84c74df87d15f5d119df268ba6aa79bc1e16a2c3"},{"fixed":"a40941e3a29720850e5b6158340d78e239b4f9a5"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.14.0","v2.13.0","v2.12.2","v2.12.1","v2.12.0","v2.11.0","v2.10.1","v2.10.0","v2.9.2","v2.9.1","v2.9.0","v2.8.5","v2.8.4","v2.8.3","v2.8.2","v2.8.1","v2.8.0","v2.7.7","v2.7.6","v2.7.5","v2.7.4","v2.7.4.beta3","v2.7.4.beta2","v2.7.4.beta1","v2.7.3","v2.7.2","v2.7.1","v2.7.0","v2.6.0","v2.5.1","v2.5","v2.4","v2.3","v2.2.1","v2.2","v2.1.1","v2.1","v2.1.pre.1","v2.0.1","v2.0","v2.0.pre.2","v2.0.pre.1","REL_1.0.0","REL_0.9.2","REL_0.9.1","REL_0.8.4","REL_0.8.3","REL_0.8.2","REL_0.8.0","REL_0.7.8","REL_0.7.7","REL_0.7.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107399.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}