<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Approval-Bypass on CuraSec</title><link>https://curasec.metacog.co.kr/tags/approval-bypass/</link><description>Recent content in Approval-Bypass on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 21 Sep 2026 18:11:48 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/approval-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>Loopjacking: AI Agent Approval Bypass in Agno and LangGraph</title><link>https://curasec.metacog.co.kr/insights/2026-09-21-loopjacking-hijacking-human-in-the-loop-approval/</link><pubDate>Mon, 21 Sep 2026 18:11:48 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-21-loopjacking-hijacking-human-in-the-loop-approval/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Confirmed post-approval state-substitution in Agno AgentOS ≤3.0.9 and LangGraph Agent Server ≤0.14.0 — if you ship AI agent workflows with human-in-the-loop gates, audit these dependencies and upgrade to patched releases; review approval-to-execution binding in any custom agent code.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Novel attack class showing that human approval gates in agentic systems can be bypassed via state mutation or misrepresentation; no IOCs or ATT&amp;amp;CK-mapped TTPs to hunt for today, but worth understanding as AI agent deployments expand detection scope.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization is deploying AI agents with human-approval checkpoints, this research establishes that approval binding is an unsolved control problem in major frameworks — use it to drive a policy review of agentic AI deployments and require vendors to document their approval-integrity guarantees this quarter.&lt;/li>
&lt;/ul></description></item></channel></rss>