Origin Trust Boundary Vulnerability in Mechanize Library by Sparklemotion
CVE-2026-107399
6.8MEDIUM
What is CVE-2026-107399?
An issue in the Mechanize library allows for origin trust boundary violations when the follow_meta_refresh feature is enabled. Attackers can manipulate meta refresh headers to reapply caller-supplied headers, potentially exposing sensitive information like bearer tokens or session cookies. Although the default setting of follow_meta_refresh is set to false, the risk may arise from custom configurations. This vulnerability is addressed in version 2.14.1, and users are encouraged to update to mitigate the risk.
Affected Version(s)
mechanize < 2.15.0
