Skip to main content
HIGH

CVE-2026-103958

CVSS v3

7.6

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent. To remediate this issue, users should upgrade to version 1.7.0 or later.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Published
2026-10-02
Last Modified
2026-10-02

Frequently asked questions

What is CVE-2026-103958?

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address supplied when registering, updating or testing a tool server or remote agent. To remediate this issue, users should upgrade to version 1.7.0 or later.

Is CVE-2026-103958 actively exploited?

Active exploitation of CVE-2026-103958 has not been confirmed.

What is the CVSS score for CVE-2026-103958?

CVE-2026-103958 has a CVSS v3 base score of 7.6 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N.

Is CVE-2026-103958 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key