AI analysis
Loom for AWS versions before 1.7.0 have a server-side request forgery flaw (CWE-918) in how tool server and remote agent connections are handled. An authenticated remote user can supply a crafted connection address when registering, updating, or testing a tool server or remote agent. The flaw may let that user obtain the credentials of the application's own container role and read responses from arbitrary internal network locations. CVSS 4.0 rates the issue 8.3 (high) and requires high privileges, with no user interaction. It is not in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade Loom for AWS to version 1.7.0 or later. Limit which authenticated users can register, update, or test tool servers and remote agents, and review those connection addresses for unexpected internal or cloud-metadata targets. If misuse is suspected, rotate the application's container role credentials and inspect logs for crafted connection addresses.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent. To remediate this issue, users should upgrade to version 1.7.0 or later.