Plan
active
Loopjacking: AI Agent Approval Bypass in Agno and LangGraph
- Engineer — Plan: Confirmed post-approval state-substitution in Agno AgentOS ≤3.0.9 and LangGraph Agent Server ≤0.14.0 — if you ship AI agent workflows with human-in-the-loop gates, audit these dependencies and upgrade to patched releases; review approval-to-execution binding in any custom agent code.
- SOC/IR — Learn: Novel attack class showing that human approval gates in agentic systems can be bypassed via state mutation or misrepresentation; no IOCs or ATT&CK-mapped TTPs to hunt for today, but worth understanding as AI agent deployments expand detection scope.
- Leader — Plan: If your organization is deploying AI agents with human-approval checkpoints, this research establishes that approval binding is an unsolved control problem in major frameworks — use it to drive a policy review of agentic AI deployments and require vendors to document their approval-integrity guarantees this quarter.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.