—
DRUPAL-CONTRIB-2026-068
Details
This module enables you to test and run AI-driven workflows interactively through a chat interface.
The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow iterates more than once. This may result in execution of workflows that were not intended by the user.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer FlowDrop workflows" (or the equivalent "Create FlowDrop workflows" / "Edit FlowDrop workflows" permissions).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8 / drupal/flowdrop
Introduced in:
0 Fixed in: 1.6.0 Upgrade drupal/flowdrop to 1.6.0 or newer (ecosystem packagist:https://packages.drupal.org/8).