CVE-2026-107399
Received Received - Intake

Open Redirect via Meta Refresh in Mechanize

Vulnerability report for CVE-2026-107399, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers configured through Mechanize#request_headers= to be reapplied to the refresh request, allowing an attacker who controls content in the crawl to capture bearer tokens or session cookies. The default configuration is not affected because follow_meta_refresh is false, and the exposure is limited to caller-supplied default headers. This issue is fixed in version 2.14.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sparklemotion mechanize < 2.15.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Mechanize library automates website interactions. Before version 2.14.1, it did not enforce origin trust boundaries when following meta refresh tags. If a page with a meta refresh to another origin was processed, headers set via Mechanize#request_headers= could be reapplied to the refresh request. This allowed attackers controlling crawl content to capture sensitive data like bearer tokens or session cookies.

Detection Guidance

This vulnerability can be detected by checking the version of the Mechanize library in use. If your system uses Mechanize version 2.14.1 or later, it is not vulnerable. For earlier versions, inspect applications that use Mechanize for meta refresh handling with follow_meta_refresh enabled.

Impact Analysis

An attacker could exploit this to steal session cookies or authentication tokens by tricking users into visiting a malicious page. This could lead to unauthorized account access or data breaches. The impact is limited to systems using Mechanize with follow_meta_refresh enabled and custom headers configured.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles or HIPAA's safeguards for protected health information. Organizations using Mechanize with affected configurations may face compliance risks if exploited.

Mitigation Strategies

Upgrade the Mechanize library to version 2.14.1 or later. If upgrading is not immediately possible, disable the follow_meta_refresh feature in Mechanize or avoid using caller-supplied default headers with meta refresh requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107399. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart