Executive brief
FlowDrop is a Drupal module used to create and manage automated workflows, including AI-driven processes. A security flaw in the module's approval system allows certain authorized users to bypass human-in-the-loop safety gates during repetitive workflow tasks. This could lead to the unintended execution of automated actions or AI processes without the required manual oversight.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Drupal FlowDrop module versions prior to 1.6.0. The module fails to sufficiently re-evaluate human-in-the-loop approval gates when a workflow iterates more than once. This allows an attacker with existing workflow administration or creation permissions to bypass intended manual approval steps, potentially leading to unauthorized execution of workflow tasks. The issue is resolved in FlowDrop version 1.6.0.
Affected products
- Drupal FlowDrop 0.0.0 to 1.5.9
Timeline
- 2026-07-01: patched: Version 1.6.0 released to address the issue.
- 2026-07-01: advisory: Drupal security advisory SA-CONTRIB-2026-068 published.
- 2026-07-10: disclosed: CVE-2026-58590 published.