Security & AI news

AI agent platform security · By FireAI Security & Research Team · Published

AWS fixes three flaws in its Loom AI agent platform, including an authentication bypass, and a SageMaker command injection

AWS patched Loom, an open-source AI agent control plane, for an authentication bypass, OAuth2 token disclosure and SSRF, plus a SageMaker Studio flaw. Loom 1.7.0 is the fix.

An AI agent icon and the FireAI agent-profile mascot, illustrating AWS fixes for authentication bypass, OAuth2 token disclosure and request forgery flaws in its Loom agent platform.

Two security news sites reported on 5 October 2026 that AWS released fixes for flaws in Loom, an open-source platform that orchestrates AI agents, and in Amazon SageMaker Unified Studio [1] [2]. Cyber Press dates the fixes to 2 October 2026 [2]. The flaws concern the control layer that decides which tools and credentials an agent can use, a layer that Mac users running agent tools locally can also meet.

Background

An agent platform keeps a registry of tool servers, stores credentials and forwards requests on an agent’s behalf. If its administration interface is open, or if it follows URLs supplied by a user, an attacker can inherit what the platform holds. The reports describe three such cases in Loom and one command injection in a SageMaker component.

Findings

The most severe flaw, CVE-2026-103956, is an authentication bypass: in deployments with no identity provider configured, an unauthenticated network client could gain “full administrative access to the agent control plane”, register malicious tool servers and reach stored credentials [1]. Cyber Press lists Loom versions before 1.6.1 as affected by this flaw [2].

CVE-2026-103957 is described as an OAuth2 token disclosure. An authenticated user with specific scopes could configure a malicious well-known discovery URL that made the Loom backend send OAuth2 client secrets, or other users’ access tokens, to an endpoint the attacker controls [1] [2]. Cyber Press lists versions before 1.7.0 as affected [2].

CVE-2026-103958 is a server-side request forgery. A user with write permissions could force the backend to connect to arbitrary internal network destinations, which could expose credential-vending services and yield temporary role credentials [1] [2]. A fourth flaw, CVE-2026-104019, affects the SageMaker Unified Studio startup script: improperly sanitised connection details allowed command injection and, per Cyber Press, arbitrary code execution inside another member’s SageMaker Space [1] [2].

Remediation, according to both sites, is to upgrade Loom to version 1.7.0; GBHackers adds that deployments should configure Amazon Cognito or an external identity provider and disable unauthenticated local development settings in production [1]. Cyber Press lists patched SageMaker Distribution versions, advises restarting affected Studio Spaces, and recommends rotating credentials and reviewing CloudTrail logs [2].

Implications for organisations and developers

The reports concern server-side deployments, so the main audience is the teams that run Loom or SageMaker Unified Studio. The common pattern, an agent control plane that trusts a URL or a network client too easily, is relevant to any person who runs agent tooling on a Mac: a local tool server without authentication, or one that follows addresses it is given, has the same exposure on a smaller scale.

Recommendations

  1. If Loom is in use, upgrade to version 1.7.0 and confirm that an identity provider is configured.
  2. Disable unauthenticated development settings before a deployment reaches production.
  3. Rotate OAuth2 client secrets and access tokens that a vulnerable deployment may have held, and review cloud audit logs.
  4. Restart SageMaker Studio Spaces on a patched distribution version.
  5. On a Mac, check that local agent tool servers listen only on the loopback address and require authentication.

Relevance to FireAI

FireAI is a firewall for one Mac, not for a cloud platform. The Agent profile recognises 19 AI agents, learns for the first 3 days which destinations each normally contacts and then flags a new destination or an upload spike for review, using only host names and byte counts. Per-app rules let a user block a destination for one app.

FireAI does not protect AWS services and does not patch Loom or SageMaker. It does not see inside an organisation’s cloud network, and it does not read the inside of an encrypted connection. It cannot tell whether a tool server on a Mac has authentication configured.

Limitations

The two sources differ in how they count and describe the flaws. GBHackers refers to three vulnerabilities in Loom, with 1.7.0 as the fix, while Cyber Press refers to four flaws across Loom and SageMaker and gives 1.6.1 as the affected boundary for the authentication bypass [1] [2]. Neither page reported exploitation in the wild, and this item did not read an AWS advisory directly.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. GBHackers, 5 October 2026: AWS fixes AI agent flaws enabling authentication bypass and credential theft
  2. Cyber Press, 5 October 2026: AWS patches Loom and SageMaker flaws allowing code execution and credential exposure