Loom
AWS · 3 CVEs
CVE-2026-103956
CRITICAL
Missing authentication for critical function in Loom for AWS
Oct 2, 2026
CVE-2026-103958
HIGH
Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS
Oct 2, 2026
CVE-2026-103957
HIGH
Server-side request forgery in the OAuth2 discovery handling in Loom for AWS
Oct 2, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-103956 | Missing authentication for critical function in Loom for AWS | CRITICAL | 0.47% | Oct 2, 2026 |
| CVE-2026-103958 | Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS | HIGH | 0.33% | Oct 2, 2026 |
| CVE-2026-103957 | Server-side request forgery in the OAuth2 discovery handling in Loom for AWS | HIGH | 0.38% | Oct 2, 2026 |
Showing 1 to 3 of 3 CVEs