CVE-2026-103957
Received Received - Intake

Server-Side Request Forgery in Loom for AWS

Vulnerability report for CVE-2026-103957, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: AMZN

Description

Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication. To remediate this issue, users should upgrade to version 1.7.0 or later.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
aws_labs loom 1.7.0
loom loom 1.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a server-side request forgery (SSRF) vulnerability in Loom for AWS before version 1.7.0. An authenticated remote user could exploit it by providing a crafted discovery document address during tool server or remote agent registration. This could allow the attacker to obtain another user's access token and make the application send requests to arbitrary internal network locations.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized OAuth2 token disclosures or SSRF attempts. Monitor outbound requests from Loom to external or internal endpoints, especially those involving OAuth2 discovery URLs. Check logs for unexpected token transmissions or requests to internal network locations. Ensure Loom is updated to version 1.7.0 or later to prevent exploitation.

Impact Analysis

An attacker could gain access to another user's OAuth2 access token, potentially leading to unauthorized access to resources. They could also cause the application to make requests to internal systems, which might expose sensitive data or enable further attacks. The impact includes credential theft and potential lateral movement within the network.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized disclosure, and non-compliance with access control and integrity requirements.

Mitigation Strategies

Immediately upgrade Loom to version 1.7.0 or later. Restrict the mcp:write and a2a:write scopes to trusted administrators until upgrading. Rotate OAuth2 client secrets, revoke and re-issue access tokens, and review IAM role credentials for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103957. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart