AI analysis
Loom for AWS before 1.6.1 is missing authentication for a critical function in its authentication dependency (CWE-306), compounded by an insecure default when no identity provider is set (CWE-1188). In that configuration, any remote request to the application API is accepted without credentials and grants super-admin authority over the agent control plane. An attacker can register tool servers, read stored integration credentials, and rewrite the IAM role policies attached to managed agent roles, with critical impact on the application and on subsequent AWS resources. Only deployments running a version older than 1.6.1 and operating with no identity provider configured are affected. The flaw is not in CISA KEV and no public proof-of-concept is known.
What to do: Upgrade Loom for AWS to version 1.6.1 or later. Until that is done, treat any deployment that has no identity provider configured as exposed: enable an identity provider, then review registered tool servers, stored integration credentials, and IAM policies on managed agent roles for unauthorized changes and rotate any credentials that may have been readable.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later.