Project: 
Date: 
2026-July-01
Vulnerability: 
Access bypass
Affected versions: 
<1.6.0
CVE IDs: 
CVE-2026-58590
Description: 

This module enables you to test and run AI-driven workflows interactively through a chat interface.

The module doesn't sufficiently re-evaluate a human-in-the-loop approval gate where the workflow iterates more than once. This may result in execution of workflows that were not intended by the user.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer FlowDrop workflows" (or the equivalent "Create FlowDrop workflows" / "Edit FlowDrop workflows" permissions).

Solution: 

Install the latest version:

  • If you use the FlowDrop module for Drupal 11.x, upgrade to FlowDrop 1.6.0
Coordinated By: