What happened
AWS disclosed an SSRF plus credential/token disclosure (CWE-918, CWE-201) in Loom's OAuth2 discovery handling, fixed in 1.7.0. The earlier 1.6.1 fix blocked internal-address reach for this path but did not fully stop the token disclosure.
Why it matters
OAuth tokens drive agent access to downstream services; leaking a victim user's agent access token or integration client secrets compromises the identity layer that the AI agent platform uses to act on behalf of users.
Attack vector
An authenticated user configures a malicious well-known OAuth2 discovery URL whose document directs the backend to send OAuth2 client secrets or another user's access token to a third-party-controlled endpoint, and to issue requests to arbitrary internal locations.
Affected systems
Loom for AWS < 1.7.0
Mitigation
Upgrade to Loom 1.7.0; limit mcp:write/a2a:write scopes; rotate OAuth2 client secrets and re-issue access tokens that were active in the affected window. Advisory: https://aws.amazon.com/security/security-bulletins/2026-124-aws/