Origin Trust Boundary Vulnerability in Mechanize Library by Sparklemotion
CVE-2026-107399

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107399?

An issue in the Mechanize library allows for origin trust boundary violations when the follow_meta_refresh feature is enabled. Attackers can manipulate meta refresh headers to reapply caller-supplied headers, potentially exposing sensitive information like bearer tokens or session cookies. Although the default setting of follow_meta_refresh is set to false, the risk may arise from custom configurations. This vulnerability is addressed in version 2.14.1, and users are encouraged to update to mitigate the risk.

Affected Version(s)

mechanize < 2.15.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.