Automation Library Vulnerability in Mechanize from Sparklemotion
CVE-2026-107715
6.8MEDIUM
What is CVE-2026-107715?
The Mechanize library, utilized for automating website interactions, contains a vulnerability wherein it inadvertently sends user-provided credential headers to an external host following an HTTP redirect. This behavior stems from the way Mechanize reprocesses headers even after stripping per-request headers during redirection. As a result, an attacker controlling the redirect target could potentially intercept sensitive information such as bearer tokens or session cookies included in those headers. It's important to note that Mechanize's cookie jar and authentication store remain unaffected. This issue has been resolved in version 2.14.1.
Affected Version(s)
mechanize < 2.15.0
