---
id: CVE-2026-103958
title: >-
  Server-side request forgery in the tool server and remote agent connection
  handling in Loom for AWS before 1.7.0 might allow an authenticated remote user
  to obtain the credentials of the application's own container role and to read
  respo…
summary: >-
  Server-side request forgery in the tool server and remote agent connection
  handling in Loom for AWS before 1.7.0 might allow an authenticated remote user
  to obtain the credentials of the application's own container role and to read
  respo…
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-918
vendor: AWS
product: loom
affected:
  - loom < 1.7.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T20:17:00.497'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103958'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-124-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/awslabs/loom/releases/tag/v1.7.0'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/awslabs/loom/security/advisories/GHSA-w6g6-h8pv-6mc7'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T22:33:09.841Z'
---

## Overview

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent.



To remediate this issue, users should upgrade to version 1.7.0 or later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
