Mechanize 库用于自动化与网站的交互。在版本 2.14.1 之前,当启用 时, 方法未实施源信任边界(origin trust boundary)检查。如果某页面包含指向其他源(origin)的 meta refresh 指令,则通过 配置的请求头会被重新应用到该重定向请求中,从而导致攻击者若能控制爬取过程中的内容,即可捕获承载令牌(bearer tokens)或会话 cookie。默认配置不受此影响,因为 默认值为 false;且该风险仅局限于调用者提供的默认请求头。此问题已在版本 2.14.1 中得到修
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sparklemotion | mechanize | < 2.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107715 | 6.8 MEDIUM | Mechanize sends credential headers to another host after an HTTP redirect |
| CVE-2026-107714 | 5.9 MEDIUM | Mechanize sends credential headers to a different scheme or port after a redirect |
No comments yet