What happened
AWS disclosed an outbound-request SSRF (CWE-918) in Loom's tool-server and remote-agent connection handling fixed in 1.7.0. A user permitted to configure MCP/A2A connections could reach arbitrary internal network locations and read responses, including the container role's credential-vending endpoint.
Why it matters
In an AWS AI deployment the container-role credentials are the effective identity of the orchestration platform; leaking them turns an authenticated configuration-privilege user into someone able to assume the AI agent platform's own AWS permissions and pivot to the broader account.
Attack vector
An authenticated user with mcp:write or a2a:write scope directs a tool-server (MCP) or remote-agent (A2A) connection to an arbitrary internal network location — including the container's own credential-vending endpoint — and reads the response, exfiltrating the application's container-role credentials.
Affected systems
Loom for AWS < 1.7.0
Mitigation
Upgrade to Loom 1.7.0; restrict mcp:write/a2a:write scopes to trusted admins; after upgrade rotate IAM session credentials and review CloudTrail. Advisory: https://aws.amazon.com/security/security-bulletins/2026-124-aws/