Mechanize Project maintains a lightweight Python library for automated web browsing and interaction, with its modest disclosure footprint centered on input handling and command-processing weaknesses such as OS command injection, regular-expression complexity, and sensitive-information exposure. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mechanize Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32837HIGH mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to | Jan 17, 2023 | 7.5 | 39 | NO | NO |
CVE-2022-31033HIGH The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies, follows redirects, and can follow links and submit forms. | Jun 9, 2022 | 7.5 | 26 | NO | NO |
CVE-2021-21289HIGH Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerabil | Feb 2, 2021 | 8.3 | 26 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mechanize Project.
Media articles that mention a CVE ID that affects a product developed by Mechanize Project — matched by CVE ID, not by vendor name.