Description
Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication.



To remediate this issue, users should upgrade to version 1.7.0 or later.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access Token Acquisition and Internal Network Access
Action: Immediate Upgrade
AI Analysis

Impact

Loom for AWS is vulnerable to a server‑side request forgery that allows an authenticated user to supply a crafted discovery document URL when registering a tool server or remote agent for delegated authentication. This flaw lets the attacker cause Loom to perform outbound requests to arbitrary internal network locations and, by exploiting the same mechanism, obtain the access token of another user in the same deployment. The weakness is a classic SSRF vulnerability (CWE‑918) compounded by inadequate authorization checks (CWE‑201), resulting in a significant confidentiality breach and potential internal network compromise.

Affected Systems

The issue affects all Loom for AWS installations using versions earlier than 1.7.0. Users running 1.6.x or any earlier release are susceptible when they allow tool server registration with delegated authentication enabled.

Risk and Exploitability

With a CVSS score of 8.2, the vulnerability is categorized as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated remote user who can register a tool server or remote agent; the attacker need not be privileged beyond valid authentication credentials. Exploitation would require providing a malicious discovery document URL, after which Loom would silently make requests to the specified internal host and the attacker could capture another user's access token.

Generated by OpenCVE AI on October 2, 2026 at 20:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading Loom to version 1.7.0 or later, which removes the SSRF (CWE‑918) flaw in discovery handling and corrects the improper authorization checks (CWE‑201).
  • If an upgrade is not possible, restrict tool‑server registration to known trusted internal URLs and disable delegated authentication for external clients until the patch is applied, thereby mitigating the unauthorized access token acquisition (CWE‑201) and limiting the potential SSRF (CWE‑918) surface area.
  • Configure networking controls (firewall rules, security groups) so that Loom can only reach necessary internal endpoints, preventing arbitrary internal network requests that could exploit the SSRF weakness (CWE‑918).
  • Continuously monitor logs for abnormal outbound requests or token retrieval patterns, and investigate any suspicious activity to detect exploitation attempts early.

Generated by OpenCVE AI on October 2, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:30:00 +0000


Fri, 02 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication. To remediate this issue, users should upgrade to version 1.7.0 or later.
Title Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
Weaknesses CWE-201
CWE-918
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-02T19:16:02.590Z

Reserved: 2026-10-01T14:59:36.668Z

Link: CVE-2026-103957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T19:16:39.893

Modified: 2026-10-02T20:17:00.390

Link: CVE-2026-103957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T21:00:18Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data

  • CWE-918

    Server-Side Request Forgery (SSRF)