Mechanize sends credential headers to another origin after a meta refresh
Published: October 08, 2026
SECURITY IDENTIFIERS
- CVE: CVE-2026-107399 (NVD)
- GHSA: GHSA-c6rp-p8xm-4q9f
GEM
SEVERITY
CVSS v3.x: 6.8 (Medium)
PATCHED VERSIONS
>= 2.14.1
DESCRIPTION
Summary
mechanize applied no trust boundary to a meta refresh, so credentials
set through Mechanize#request_headers= followed a refresh that
pointed at another origin.
Details
Mechanize::HTTP::Agent#response_follow_meta_refresh fetched the refresh
target with no notion of a crossed origin, so @request_headers were
re-applied in full. An attacker who could place a meta refresh in a
page the agent fetched — through stored content, an open redirect, or
control of any page in the crawl — collected the same credentials as
through an HTTP redirect, on a code path that had none of the redirect
path's protections.
The refresh fetch passes an empty per-request headers hash, so only
headers set through Mechanize#request_headers= were exposed.
This requires Mechanize#follow_meta_refresh = true. It is false
by default, so an agent in its default configuration is not affected.
Crawlers commonly enable it.
Impact
An attacker who can place a meta refresh in any page the agent fetches
captures bearer tokens and session cookies set through request_headers=.
Disclosure only; no integrity or availability impact.
RELATED
- https://nvd.nist.gov/vuln/detail/CVE-2026-107399
- https://rubygems.org/gems/mechanize/versions/2.14.1
- https://github.com/sparklemotion/mechanize/releases/tag/v2.14.1
- https://github.com/sparklemotion/mechanize/blob/main/CHANGELOG.md#2141--2026-08-22
- https://github.com/sparklemotion/mechanize/pull/676
- https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f
- https://github.com/sparklemotion/mechanize/commit/84c74df87d15f5d119df268ba6aa79bc1e16a2c3
- https://advisories.gitlab.com/gem/mechanize/CVE-2026-107399
- https://github.com/sparklemotion/mechanize/security/advisories/GHSA-c6rp-p8xm-4q9f
- https://github.com/advisories/GHSA-c6rp-p8xm-4q9f
