Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-107715: CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections

CVE-2026-107715: Information Disclosure and Credential Leakage in Ruby Mechanize via Cross-Origin Redirections Vulnerability ID: CVE-2026-107715 CVSS Score: 6.8 Published: 2026-10-08 Ruby Mechanize prior to version 2.14.1 contains an information disclosure vulnerability. When executing cross-origin HTTP redirects, global headers configured on the Mechanize agent (such as Authorization or Session…

CVE-2026-107715 identifies a security vulnerability impacting the Ruby Mechanize library prior to version 2.14.1. This flaw allows information disclosure and credential leakage through cross-origin HTTP redirects. When Mechanize agents perform cross-origin redirects, global headers like Authorization tokens or session cookies are erroneously re-applied to subsequent requests.

This bypasses the system's internal header-stripping mechanism. An attacker controlling the redirection endpoint could capture sensitive bearer tokens or session cookies. The vulnerability is rated with a CVSS score of 6.8, classified as medium severity. Although a Proof of Concept (PoC) exploit is available, as of now, there is no official exploit in circulation.

This issue has been addressed in Ruby Mechanize version 2.14.1, which patches the header-stripping logic in redirects. Upgrading to this version is strongly recommended to mitigate the risk.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Give Your API Agent a Definition of Done

An agent calls createProject, gets a valid response, and announces that the project is ready. Then the next request cannot find it. The tool call succeeded. The workflow did not.

  • Define a clear "Definition of Done" for API agents with create-read-check process
  • Implement four-step workflow: create project, read project, compare details, clean up
  • Use OpenAPI document as basis for AI-assisted API work and debugging

More from Friday 9 October →