Impact
Loom for AWS is vulnerable to a server‑side request forgery that allows an authenticated user to supply a crafted discovery document URL when registering a tool server or remote agent for delegated authentication. This flaw lets the attacker cause Loom to perform outbound requests to arbitrary internal network locations and, by exploiting the same mechanism, obtain the access token of another user in the same deployment. The weakness is a classic SSRF vulnerability (CWE‑918) compounded by inadequate authorization checks (CWE‑201), resulting in a significant confidentiality breach and potential internal network compromise.
Affected Systems
The issue affects all Loom for AWS installations using versions earlier than 1.7.0. Users running 1.6.x or any earlier release are susceptible when they allow tool server registration with delegated authentication enabled.
Risk and Exploitability
With a CVSS score of 8.2, the vulnerability is categorized as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated remote user who can register a tool server or remote agent; the attacker need not be privileged beyond valid authentication credentials. Exploitation would require providing a malicious discovery document URL, after which Loom would silently make requests to the specified internal host and the attacker could capture another user's access token.
OpenCVE Enrichment