mechanize
RubyGems4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mechanizepage 1 of 1
- CVE-2021-21289HIGHCVSS 7.4EG 7.4fixed in 2.7.72021-02-02
vulnerable: 2.0 ... 2.7.6 (19 versions)
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands t…
- CVE-2022-31033MEDIUMCVSS 5.9EG 5.9fixed in 2.8.52022-06-09
vulnerable: 0.1.0 ... 2.8.4 (83 versions)
The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies, follows redirects, and can follow links and submit forms. In versions prior to 2.8.5 the Authorization header is leak…
- CVE-2026-107399MEDIUMCVSS 6.8EG 6.8fixed in 2.14.12026-10-08
vulnerable: 0.1.0 ... 2.9.2 (95 versions)
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize applies no origin trust boundary in Mechanize::HTTP::Agent#response_follow_meta_refresh when Mechanize#follow_meta_refresh is enabled. A pag…
- CVE-2026-107715MEDIUMCVSS 6.8EG 6.8fixed in 2.14.12026-10-08
vulnerable: 0.1.0 ... 2.9.2 (95 versions)
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::H…
Check whether mechanize is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mechanize CVEs against the assets you own.
Book a Demo →