---
id: CVE-2026-103957
title: >-
  Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
  before 1.7.0 might allow an authenticated remote user to obtain the access
  token of another user of the deployment and to cause the application to issue
  request…
summary: >-
  Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
  before 1.7.0 might allow an authenticated remote user to obtain the access
  token of another user of the deployment and to cause the application to issue
  request…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N'
cwe:
  - CWE-201
  - CWE-918
vendor: AWS
product: loom
affected:
  - loom < 1.7.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T20:17:00.390'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103957'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-124-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/awslabs/loom/releases/tag/v1.7.0'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/awslabs/loom/security/advisories/GHSA-jcxf-gpf4-58hm'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T22:33:09.841Z'
---

## Overview

Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication.



To remediate this issue, users should upgrade to version 1.7.0 or later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
