CVE-2026-107714 | Sparklemotion Mechanize up to 2.14.0 Response Redirect Agent#response_redirect cross-domain policy

SecurityVulns

A vulnerability was found in Sparklemotion Mechanize up to 2.14.0. It has been rated as problematic. Affected is the function Mechanize::HTTP::Agent#response_redirect of the component Response Redirect. The manipulation leads to permissive cross-domain policy with untrusted domains.

This vulnerability is uniquely identified as CVE-2026-107714. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More