RubySec

Providing security resources for the Ruby community

CVE-2026-107399 (mechanize): Mechanize sends credential headers to another origin after a meta refresh

Mechanize sends credential headers to another origin after a meta refresh

Published: October 08, 2026

SECURITY IDENTIFIERS

GEM

mechanize

SEVERITY

CVSS v3.x: 6.8 (Medium)

PATCHED VERSIONS

>= 2.14.1

DESCRIPTION

Summary

mechanize applied no trust boundary to a meta refresh, so credentials set through Mechanize#request_headers= followed a refresh that pointed at another origin.

Details

Mechanize::HTTP::Agent#response_follow_meta_refresh fetched the refresh target with no notion of a crossed origin, so @request_headers were re-applied in full. An attacker who could place a meta refresh in a page the agent fetched — through stored content, an open redirect, or control of any page in the crawl — collected the same credentials as through an HTTP redirect, on a code path that had none of the redirect path's protections.

The refresh fetch passes an empty per-request headers hash, so only headers set through Mechanize#request_headers= were exposed.

This requires Mechanize#follow_meta_refresh = true. It is false by default, so an agent in its default configuration is not affected. Crawlers commonly enable it.

Impact

An attacker who can place a meta refresh in any page the agent fetches captures bearer tokens and session cookies set through request_headers=. Disclosure only; no integrity or availability impact.

RELATED