Skip to main content

CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS

Bulletin ID: 2026-124-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/02/2026 12:00 PM PDT

Description:

Loom is an AWS Labs open-source AI agent orchestration platform. We have identified and addressed three issues in Loom for AWS, described below. We recommend upgrading to the latest version (1.7.0) and ensuring any forked or derivative code is patched to incorporate the new fixes.

  • CVE-2026-103956 — Authentication bypass in Loom for AWS (CWE-306, CWE-1188) An issue in the authentication dependency in Loom for AWS versions <1.6.1 allowed any network client to obtain full administrative authority over the agent control plane — including registering tool servers, reading stored integration credentials, and rewriting IAM role policies attached to managed agent roles — via any request to the application API in a deployment where no identity provider was configured. This issue was addressed in version 1.6.1, released 2026-08-04.
  • CVE-2026-103957 — OAuth2 token and credential disclosure via outbound request handling in Loom for AWS (CWE-918, CWE-201) An issue in the OAuth2 discovery handling in Loom for AWS versions <1.7.0 allowed an authenticated user with the mcp:write or a2a:write scope to configure a well-known discovery URL whose document directed the backend to send OAuth2 client secrets or another user's access token to a third-party-controlled endpoint. The 1.6.1 release blocked internal-address reach for this code path but did not fully address the token disclosure. This issue was fully addressed in version 1.7.0.
  • CVE-2026-103958 — Outbound request handling issue in tool server and remote agent connections in Loom for AWS (CWE-918) An issue in the tool server (MCP) and remote agent (A2A) connection handling in Loom for AWS versions <1.7.0 allowed an authenticated user with the mcp:write or a2a:write scope to direct connection requests to arbitrary internal network locations — including the container's credential-vending endpoint — and read the responses. This issue was addressed in version 1.7.0.

Resolution:

These issues have been addressed in Loom version 1.7.0. CVE-2026-103956 was independently addressed in version 1.6.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

Until upgrading:

  • For CVE-2026-103956: Ensure a Cognito user pool or an active external identity provider is fully configured before the backend is reachable beyond loopback, and confirm LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV is unset in any deployed (non-local-dev) environment.
  • For CVE-2026-103957 and CVE-2026-103958: Restrict the mcp:write, and a2a:write scopes (i.e., g-admins-super, g-admins-mcp, g-admins-a2a, g-admins-demo group membership) to trusted administrators only. This reduces the likelihood of these issues being triggered but does not fully close the issue without the code fix.

After upgrading:

  1. Rotate any OAuth2 client secrets configured for MCP/A2A integrations
  2. Revoke and re-issue any access tokens that were active during the affected window
  3. If container role credentials were accessed, rotate the IAM role's session credentials and review CloudTrail for unintended usage.

References:

Acknowledgement:

We would like to thank Kenneth Cox for collaborating on this issue through the coordinated disclosure process.


Please email aws-security@amazon.com with any security questions or concerns.