{"id":"DRUPAL-CONTRIB-2026-067","details":"This module enables you to test and run AI-driven workflows interactively through a chat interface.\n\nThe module doesn't sufficiently enforce permissions on certain endpoints. Attackers may be able to trigger workflow execution (incurring LLM spend and tool side effects) or send messages into other user's sessions.\n\nThis vulnerability is mitigated by the fact that an attacker must have the permission \"View any session\", which is not granted to anonymous or authenticated users by default.","aliases":["CVE-2026-58589"],"modified":"2026-09-10T03:45:03.277127716Z","published":"2026-07-01T17:21:57Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-067"}],"affected":[{"package":{"name":"drupal/flowdrop","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/flowdrop?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.0"}],"database_specific":{"constraint":"\u003c1.6.0"}}],"database_specific":{"affected_versions":"\u003c1.6.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/flowdrop/DRUPAL-CONTRIB-2026-067.json"}}],"schema_version":"1.9.0","credits":[{"name":"Aincient Labs  (aincient labs)","contact":["https://www.drupal.org/u/aincient-labs"]}]}