CVE-2026-103957: Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication.
To remediate this issue, users should upgrade to version 1.7.0 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Loom for AWSto a version that resolves this vulnerability.Fixed in 1.7.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated remote user can exploit it if they can register a tool server or remote agent configured for delegated authentication and supply a crafted OAuth2 discovery document address.
What can an attacker do with successful exploitation?
The attacker might obtain another deployment user's access token and cause the application to send requests to arbitrary internal network locations.
Which versions need remediation?
Loom for AWS versions before 1.7.0 are affected. Upgrade to version 1.7.0 or later to remediate the issue.