CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS
Summary
AWS Labs identified three security vulnerabilities in Loom, an open-source AI agent orchestration (system for managing multiple AI agents) platform for AWS. The issues range from an authentication bypass that could let anyone gain admin access when no identity provider is set up, to credential disclosure flaws that could leak OAuth2 tokens (security credentials used for authorization) and allow unauthorized access to internal network resources.
Solution / Mitigation
Upgrade to Loom version 1.7.0, which fully addresses all three vulnerabilities. The source explicitly states: 'We recommend upgrading to the latest version (1.7.0) and ensuring any forked or derivative code is patched to incorporate the new fixes.' Note that version 1.6.1 (released 2026-08-04) addressed CVE-2026-103956 but only partially mitigated CVE-2026-103957.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-124-aws/
First tracked: October 2, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%