Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #2
Loopjacking attack swaps approved actions in AI agent workflows
Original: An approval prompt only protects you if the action you approved is the one that runs. Loopjacking swaps it after the cli
Security researchers are warning about a new attack technique called loopjacking, which exploits mutable workflow state in AI agent servers. The flaw means an approval prompt can be shown for one action, but a different action runs after the user clicks approve. The issue has been reproduced in certain versions of Agno AgentOS and LangGraph Agent Server, while OpenAI's Agents SDK reportedly resists the attack by binding approval to the exact action requested.
Why now: Fresh cybersecurity research shows that AI agent approval prompts, widely assumed to be a safety mechanism, can be bypassed in popular frameworks.
Agno AgentOSLangGraph Agent ServerOpenAI Agents SDK
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/1862759