CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107399

MEDIUMCVSS 6.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107399 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107399

MEDIUMCVSS 6.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A page containing a meta refresh to another origin causes headers

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]