Vulnerability  ·  2026-10-03

Loom for AWS: SSRF in tool-server/A2A handling leaks container-role credentials and reads internal responses (CVSS 7.6)

VulnerabilityHigh impactGlobalCVE-2026-103958
AWS disclosed an outbound-request SSRF (CWE-918) in Loom's tool-server and remote-agent connection handling fixed in 1.7.0. A user permitted to configure MCP/A2A connections could reach arbitrary internal network locations and read responses, including the container role's credential-vending endpoint.
In an AWS AI deployment the container-role credentials are the effective identity of the orchestration platform; leaking them turns an authenticated configuration-privilege user into someone able to assume the AI agent platform's own AWS permissions and pivot to the broader account.
An authenticated user with mcp:write or a2a:write scope directs a tool-server (MCP) or remote-agent (A2A) connection to an arbitrary internal network location — including the container's own credential-vending endpoint — and reads the response, exfiltrating the application's container-role credentials.
Loom for AWS < 1.7.0
Upgrade to Loom 1.7.0; restrict mcp:write/a2a:write scopes to trusted admins; after upgrade rotate IAM session credentials and review CloudTrail. Advisory: https://aws.amazon.com/security/security-bulletins/2026-124-aws/
NVD CVE-2026-103958AWS Security Bulletin 2026-124
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →