Automation Library Vulnerability in Mechanize from Sparklemotion
CVE-2026-107715

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107715?

The Mechanize library, utilized for automating website interactions, contains a vulnerability wherein it inadvertently sends user-provided credential headers to an external host following an HTTP redirect. This behavior stems from the way Mechanize reprocesses headers even after stripping per-request headers during redirection. As a result, an attacker controlling the redirect target could potentially intercept sensitive information such as bearer tokens or session cookies included in those headers. It's important to note that Mechanize's cookie jar and authentication store remain unaffected. This issue has been resolved in version 2.14.1.

Affected Version(s)

mechanize < 2.15.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.