GHSA-c6rp-p8xm-4q9f

Suggest an improvement
Source
https://github.com/advisories/GHSA-c6rp-p8xm-4q9f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-c6rp-p8xm-4q9f/GHSA-c6rp-p8xm-4q9f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c6rp-p8xm-4q9f
Aliases
  • CVE-2026-107399
Published
2026-10-08T22:09:03Z
Modified
2026-10-08T22:30:20Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Mechanize sends credential headers to another origin after a meta refresh
Details

Summary

mechanize applied no trust boundary to a meta refresh, so credentials set through Mechanize#request_headers= followed a refresh that pointed at another origin.

Details

Mechanize::HTTP::Agent#response_follow_meta_refresh fetched the refresh target with no notion of a crossed origin, so @request_headers were re-applied in full. An attacker who could place a meta refresh in a page the agent fetched — through stored content, an open redirect, or control of any page in the crawl — collected the same credentials as through an HTTP redirect, on a code path that had none of the redirect path's protections.

The refresh fetch passes an empty per-request headers hash, so only headers set through Mechanize#request_headers= were exposed.

This requires Mechanize#follow_meta_refresh = true. It is false by default, so an agent in its default configuration is not affected. Crawlers commonly enable it.

Impact

An attacker who can place a meta refresh in any page the agent fetches captures bearer tokens and session cookies set through request_headers=. Disclosure only; no integrity or availability impact.

Patches

Fixed in mechanize v2.14.1. A meta refresh that points at another origin is now subject to the same rule as an HTTP redirect: credentials and cookies are withheld from the request that follows it.

Workarounds

Leave Mechanize#follow_meta_refresh at its default of false, or avoid request_headers= for credentials when it is enabled.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-522"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T22:09:03Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

RubyGems / mechanize

Package

Name
mechanize
Purl
pkg:gem/mechanize

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.14.1

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.6.9
0.6.10
0.6.11
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.9.0
0.9.1
0.9.2
0.9.3
1.*
1.0.0
1.0.1.beta.20110107104205
2.*
2.0.pre.1
2.0.pre.2
2.0
2.0.1
2.1.pre.1
2.1
2.1.1
2.2
2.2.1
2.3
2.4
2.5
2.5.1
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.9.0
2.9.1
2.9.2
2.10.0
2.10.1
2.11.0
2.12.0
2.12.1
2.12.2
2.13.0
2.14.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-c6rp-p8xm-4q9f/GHSA-c6rp-p8xm-4q9f.json"