AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

SummarizationMiddleware Bypasses PIIMiddleware And Sends Unredacted History To The Summary Model

SummarizationMiddleware invokes the summary model directly inside its before_model hook, bypassing the agent middleware pipeline. This means PIIMiddleware (including strategy='block') never inspects or redacts the summary prompt, allowing PII such as email addresses to be sent to an external summarization provider silently. The issue occurs regardless of middleware ordering in the affected versions unless external sanitization is added.

highConfidence 90%LangchainAffected V1.4.2

Origin Analysis

SummarizationMiddleware._create_summary and _acreate_summary call self._summary_model.invoke/ainvoke directly without routing the call through the agent middleware pipeline. Consequently, earlier middleware state transformations are not applied to the summary input, and later PIIMiddleware hooks cannot block the call. The summarization then replaces original messages, removing evidence of the unredacted PII.
Run the provided Python script with a RecordingSummaryModel, a history of six messages containing an email, and middleware=[SummarizationMiddleware(model=RecordingSummaryModel(), trigger=('messages',5), keep=('messages',2)), PIIMiddleware('email', strategy='block')]. Observe output: summary_model_called=1, summary_prompt_contains_email=True, pii_block_raised=False.

Fixing Code Block

Edge Case Audit

This is not a default protection: unless operators pass a sanitizer matching their PIIMiddleware rules, the leak persists. It only covers SummarizationMiddleware; LLMToolSelectorMiddleware and LLMToolEmulator may have similar direct model calls. The sanitizer must be thread-safe and stateless for concurrent runs and async use. Rolling back requires removing summary_input_sanitizer or setting it to None; no database or schema migration is needed.

Ecosystem Topology