View online: https://www.drupal.org/sa-contrib-2026-068 Project: FlowDrop [1] Date: 2026-July-01 Security risk: *Moderately critical* 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2] Vulnerability: Access bypass Affected versions: <1.6.0 CVE IDs: CVE-2026-58590 Description: This module enables you to test and run AI-driven workflows interactively through a chat interface. The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow iterates more than once. This may result in execution of workflows that were not intended by the user. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer FlowDrop workflows" (or the equivalent "Create FlowDrop workflows" / "Edit FlowDrop workflows" permissions). Solution: Install the latest version: * If you use the FlowDrop module for Drupal 11.x, upgrade to FlowDrop 1.6.0 [3] Reported By: * Aincient Labs (aincient labs) [4] Fixed By: * Shibin Das (d34dman) [5] Coordinated By: * Greg Knaddison (greggles) [6] of the Drupal Security Team * Neil Drumm (drumm) [7] of the Drupal Security Team * Juraj Nemec (poker10) [8] of the Drupal Security Team * Dave Long (longwave) [9] of the Drupal Security Team Security issue: https://git.drupalcode.org/security/3592075-flowdrop-security/-/work_items/1 [10] ------------------------------------------------------------------------------ Contribution record [11] [1] https://www.drupal.org/project/flowdrop [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/flowdrop/releases/1.6.0 [4] https://www.drupal.org/u/aincient-labs [5] https://www.drupal.org/u/d34dman [6] https://www.drupal.org/u/greggles [7] https://www.drupal.org/u/drumm [8] https://www.drupal.org/u/poker10 [9] https://www.drupal.org/u/longwave [10] https://git.drupalcode.org/security/3592075-flowdrop-security/-/work_items/1 [11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....