—
DRUPAL-CONTRIB-2026-068
상세
This module enables you to test and run AI-driven workflows interactively through a chat interface.
The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow iterates more than once. This may result in execution of workflows that were not intended by the user.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer FlowDrop workflows" (or the equivalent "Create FlowDrop workflows" / "Edit FlowDrop workflows" permissions).
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Packagist:https://packages.drupal.org/8 / drupal/flowdrop
최초 영향 버전:
0 수정 버전: 1.6.0 Upgrade drupal/flowdrop to 1.6.0 or newer (ecosystem packagist:https://packages.drupal.org/8).