VDB
KO

DRUPAL-CONTRIB-2026-067

Details

This module enables you to test and run AI-driven workflows interactively through a chat interface.

The module doesn't sufficiently enforce permissions on certain endpoints. Attackers may be able to trigger workflow execution (incurring LLM spend and tool side effects) or send messages into other user's sessions.

This vulnerability is mitigated by the fact that an attacker must have the permission "View any session", which is not granted to anonymous or authenticated users by default.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/flowdrop
Introduced in: 0 Fixed in: 1.6.0

Upgrade drupal/flowdrop to 1.6.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References