CVE-2026-107399: CVE-2026-107399: Information Disclosure via HTML Meta-Refresh in Ruby Mechanize
CVE-2026-107399: Information Disclosure via HTML Meta-Refresh in Ruby Mechanize Vulnerability ID: CVE-2026-107399 CVSS Score: 6.8 Published: 2026-10-08 An origin trust boundary failure in the Ruby mechanize library
CVE-2026-107399: Information Disclosure via HTML Meta-Refresh in Ruby Mechanize
Vulnerability ID: CVE-2026-107399
CVSS Score: 6.8
Published: 2026-10-08
An origin trust boundary failure in the Ruby mechanize library (prior to v2.14.1) allows unauthenticated remote web servers to harvest sensitive global request headers, such as Authorization Bearer tokens and cookies, by utilizing HTML-level meta-refresh redirection tags. Standard HTTP-level redirect boundaries were not applied to document-level redirects, creating a vector for cross-origin credential leakage during automated crawls.
TL;DR
Ruby Mechanize prior to version 2.14.1 fails to enforce origin trust boundaries when executing HTML meta-refreshes, allowing third-party hosts to exfiltrate globally configured request headers.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-200
- Attack Vector: Network
- CVSS Score: 6.8
- Exploit Status: poc
- KEV Status: Not Listed
- Impact: High Confidentiality Loss
- Affected Component: Mechanize::HTTP::Agent
Affected Systems
- Ruby systems running mechanize gem versions prior to 2.14.1
-
mechanize: < 2.14.1 (Fixed in:
2.14.1)
Code Analysis
Commit: 84c74df
Meta-Refresh Origin Drop
Commit: 02a1235
Stateful Header Lifetime Tracking
Commit: 6ce26d2
Header Normalization/Regression Fix
Commit: 2f97fe3
RFC 6454 Alignment & Scheme Checks
Commit: ac49abf
Additional Proxy/Cookie2 Header Coverage
Mitigation Strategies
- Upgrade the Ruby mechanize gem to version 2.14.1 or higher.
- Disable automatic meta-refresh tracking by setting follow_meta_refresh to false.
- Avoid configuring sensitive credentials globally on the Mechanize agent object; use per-request headers instead.
Remediation Steps:
- Inspect the Gemfile.lock file to determine the current version of the mechanize library.
- Update the Gemfile dependency statement to require mechanize version >= 2.14.1.
- Execute
bundle update mechanizewithin the application environment to fetch the patch. - Verify that any automated scripts that rely on request_headers do not process untrusted, user-supplied content without disabling follow_meta_refresh.
References
Read the full report for CVE-2026-107399 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.