What happened
Verified via NVD REST API (published 2026-10-08): a trio of redirect-following flaws in Mechanize < 2.14.1 — reapplication of caller-supplied credential headers to a different host after redirect, meta-refresh transactions to another origin without a trust boundary, and redirects considered same-origin on host match only (ignoring scheme/port). Together they let a page the agent fetches steer credentials to an attacker-controlled origin.
Why it matters
Mechanize is a common HTTP automation library that agentic/LLM web-automation tooling builds on; the redirect flaws are a credential-exfiltration path where fetching attacker-influenced content (or a malicious page an agent is instructed to visit) leaks the agent's stored Authorization/Cookie headers to the attacker — directly relevant to agent browsing and scraping surfaces.
Attack vector
The automation client follows a redirect or meta-refresh to an attacker host while still applying caller-supplied credential headers (request_headers= reapplied post-redirect; same-host HTTPS→HTTP redirect treated as same origin), so the attacker origin receives Authorization/Cookie headers or other sensitive headers.
Affected systems
Mechanize (Ruby) < 2.14.1 when follow_meta_refresh or redirect following is enabled (CVE-2026-107715 credential reapplication on redirect; CVE-2026-107714 inconsistent same-origin comparison; CVE-2026-107399 meta-refresh origin confusion)
Mitigation
Upgrade to Mechanize 2.14.1; fix commit https://github.com/sparklemotion/mechanize/commit/02a1235842d6eda8d4a5a3d8f13aba2cecf52e4f