FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068
Project: FlowDropDate: 2026-July-01Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <1.6.0CVE IDs: CVE-2026-58590Description: This module enables you to test and run AI-driven workflows interactively through a chat interface.
The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow iterates more than once. This may result in execution of workflows that were not intended by the user.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer FlowDrop workflows" (or the equivalent "Create FlowDrop workflows" / "Edit FlowDrop workflows" permissions).Solution: Install the latest version:
- If you use the FlowDrop module for Drupal 11.x, upgrade to FlowDrop 1.6.0
Reported By:
Fixed By:
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team

