Description
Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent.



To remediate this issue, users should upgrade to version 1.7.0 or later.
Published: 2026-10-02
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Sensitive internal credential disclosure
Action: Patch immediately
AI Analysis

Impact

Loom for AWS is vulnerable to a server‑side request forgery that is triggered when a user supplies a crafted connection address during the registration, update, or test of a tool server or remote agent. Since the request is executed from the Loom container, an authenticated remote user can obtain the credentials tied to the container’s IAM role and can read responses from any internal network endpoint addressed by the crafted URL. This gives the attacker the ability to harvest AWS credentials that grant access to resources in the same account and to exfiltrate data from the internal network, potentially leading to account compromise and data leakage.

Affected Systems

Amazon Web Services’ Loom product (AWS:loom) running any version earlier than 1.7.0 is affected. The vulnerability is present in the tool server and remote agent connection handling modules. No other vended products or services are listed as affected.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating high impact. Because the EPSS score is not provided, the current exploitation probability is unknown, but the absence of a KEV listing suggests no public exploits are documented yet. Exploitation requires an authenticated user within Loom, but once authenticated the attacker can target arbitrary internal addresses without additional permissions. The attack can be performed without elevating privileges beyond the scope of the Loom service role, making it a significant risk for environments where Loom is exposed to external users.

Generated by OpenCVE AI on October 2, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Loom to version 1.7.0 or later to apply the vendor patch.
  • If an immediate upgrade is not possible, validate and restrict the connection addresses for tool servers and remote agents so that only approved internal or external endpoints are allowed.
  • Monitor IAM role usage and inspect logs for unusual requests originating from Loom containers to detect potential credential theft early.

Generated by OpenCVE AI on October 2, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:30:00 +0000


Fri, 02 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent. To remediate this issue, users should upgrade to version 1.7.0 or later.
Title Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-02T19:18:06.426Z

Reserved: 2026-10-01T14:59:37.091Z

Link: CVE-2026-103958

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T19:16:40.040

Modified: 2026-10-02T20:17:00.497

Link: CVE-2026-103958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)