AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials

AWS released fixes for four vulnerabilities in its open-source Loom AI agent orchestration platform and SageMaker Unified Studio. The flaws could allow authentication bypass, theft of OAuth2 tokens and temporary cloud credentials, access to internal services, and arbitrary code execution in another user’s SageMaker environment.

Edward Kiledjian @ekiledjian