AE-JR9HK0TH
Human-in-the-loop middleware silently drops an invalid approval config, so a tool listed for approval runs unattended
AUTHORITY ERRORseverity: HIGHcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: LOW
HumanInTheLoopMiddleware discarded any interrupt_on entry without a truthy allowed_decisions key (a typo'd key, an empty list, or a when-only config) without error or warning. The tool the user explicitly listed for human approval, in the reproduction a delete_database call, then executed with no interrupt.
- Framework / agent
- LangChain · tool-calling agent with human-in-the-loop approval middleware
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE HumanInTheLoopMiddleware silently auto-approves tools whose `InterruptOnConfig` is invalid (typo'd or missing `allowed_decisions`) — github.com/langchain-ai/langchain, retrieved 2026-09-29
- GITHUB PULL REQUEST fix(langchain): stop HITL approval gates from silently failing open — github.com/langchain-ai/langchain, retrieved 2026-09-29
Symptoms
- The resolved interrupt_on mapping is empty and after_model returns None, so the gated tool call proceeds without an interrupt
- No exception or warning is raised for the misconfigured approval gate
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-JR9HK0TH. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.