AE-FPJJDB6B
Concurrent invocations of a shared singleton agent leak one customer's conversation data into another thread
CONCURRENCY FAILUREseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: HIGH
In a production multi-tenant chatbot, a singleton createAgent instance with a Postgres checkpointer was invoked concurrently for different thread_ids; one thread's tool call used another customer's order data and another thread addressed a customer by a nickname from a different conversation. The maintainer fix stops root-level invokes with an explicit thread_id from inheriting internal configurable entries from AsyncLocalStorage, which could belong to another concurrent invocation.
- Framework / agent
- LangGraph.js / LangChain.js · production customer-service chatbot agent (createAgent) with tools
- Remediation attempts
- TESTEDTESTEDSUGGESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE Cross-thread checkpoint data contamination when using singleton agent with concurrent invocations — github.com/langchain-ai/langgraphjs, retrieved 2026-09-29
- GITHUB PULL REQUEST fix(langgraph): isolate concurrent singleton-agent invocations by thread — github.com/langchain-ai/langgraphjs, retrieved 2026-09-29
- GITHUB PULL REQUEST fix(langgraph): merge instead of overwrite in ensureLangGraphConfig — github.com/langchain-ai/langgraphjs, retrieved 2026-09-29
Symptoms
- Data from one conversation thread appears in another thread's checkpoint and LLM responses
- The agent called an order-summary tool with another customer's data that was not in the thread's history
- A valid payment was compared against another customer's total and wrongly escalated to a human
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-FPJJDB6B. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.