In plain language
What this advisory means
Amazon Web Services (AWS) found and fixed three security problems in their open-source AI platform called Loom. These problems could allow attackers to bypass authentication, expose sensitive OAuth2 tokens and credentials, and mishandle outbound requests between parts of the system. AWS recommends upgrading Loom to version 1.7.0 and applying these fixes to any modified versions. Until then, there are temporary steps to reduce risk.
Technical explanation
How the issue affects the environment
Loom for AWS, an AI agent orchestration platform from AWS Labs, had three significant security issues. CVE-2026-103956 involves an authentication bypass caused by flaws in an authentication dependency, referencing CWE-306 and CWE-1188, which could allow unauthorized access. CVE-2026-103957 concerns disclosure of OAuth2 tokens and credentials through improper handling of outbound requests during OAuth2 discovery, classified as CWE-918 and CWE-201. CVE-2026-103958 relates to outbound request handling problems in the tool server (MCP) and remote agent (A2A) connections, also of type CWE-918. These issues were resolved in Loom version 1.7.0, with the first issue separately fixed in 1.6.1. Workarounds include configuring secure identity providers, restricting certain admin scopes to trusted users, and unsetting insecure environment variables. Post-upgrade, rotation of OAuth2 client secrets, re-issuance of tokens, and inspection or rotation of IAM session credentials through CloudTrail monitoring are advised.
Operational impact
Why teams should care
If exploited, these vulnerabilities could let attackers bypass authentication, gain unauthorized access to OAuth2 tokens and credentials, or disrupt communication between the parts of the Loom platform. This could lead to unauthorized actions, data leaks, or interference with AI agent orchestration workflows. Organizations using Loom, especially customized or forked versions, risk exposure or compromise until patched and properly configured.
Immediate action
Upgrade Loom to version 1.7.0, and ensure any forked or derived code includes these fixes. After upgrading, rotate OAuth2 client secrets and active access tokens used during the vulnerable period. If container role credentials were accessed, rotate the associated IAM role session credentials and monitor CloudTrail logs for unapproved activity.
Affected and fixed releases
Temporary risk reduction
For CVE-2026-103956: Configure a fully active Cognito user pool or external identity provider before exposing the backend outside loopback. Ensure the environment variable LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV is unset in production. For CVE-2026-103957 and CVE-2026-103958: Limit the mcp:write and a2a:write scopes to trusted administrators only, such as specific admin groups. These steps reduce risk but do not fully eliminate the vulnerabilities without patching.
Evidence and validation checklist
- AWS Security Bulletin 2026-124-AWS published 2026-10-02
- CVE entries CVE-2026-103956, CVE-2026-103957, CVE-2026-103958
- AWS public blog and documentation referencing Loom fixes
- Acknowledgement to Kenneth Cox via coordinated disclosure process
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
