Drupal security updates, in plain English

Week of 1 July 2026

Drupal publishes security updates on Wednesdays. This week there were 3, all for modules. Between them they carry 5 security fixes, because a module can fix several bugs in one update: Drupal Canvas fixed 2 and FlowDrop fixed 2.

None for Drupal core, so nothing here applies to every site.

Each card says what the module does, what went wrong, who could do it, whether it applies to you, how urgent it is, and the one line to send to your developer. Worst rated first, and most used first within a rating.

New here? How Drupal security updates work explains who publishes these, why they matter and what the ratings mean. Earlier weeks and a search by module are on the main page.

Moderately critical: 3 updates

Include in your next routine update, within the month.

Colorbox

Moderately critical · 125,407 sites report using it · SA-CONTRIB-2026-069 · on drupal.org

This module displays content in a box that appears over the top of the current page.

A person with an account could add hidden code to the site. This code could allow them to see private information or modify existing content.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if a user has an access right that allows them to enter HTML content.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Colorbox to 2.1.5 or 2.2.1, whichever branch you are on.

For developers: what the fix changed

The fix in js/colorbox.js deletes dangerous data attributes cboxCreateiframe and cboxCreateimg and sanitises cboxImgAttrs by restricting it to a safe list of attributes and aria attributes.

2.1.4 to 2.1.5 1 commit, 1 file.

  • js/colorbox.js +41 −0 fix

Full diff, 2.1.4 to 2.1.5 · Full diff, 2.2.0 to 2.2.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

Drupal Canvas

Moderately critical · 11,747 sites report using it · 2 security fixes

This module allows people to build their website design in a browser and upload image files.

2 security fixes in one update. Drupal Canvas fixed 2 separate security bugs this week: 2 improper validation. One update covers all of them. The most serious, SA-CONTRIB-2026-066, is explained here and the full list is at the end of the card.

A person with an account could upload a dangerous file that pretends to be an image. This file could execute hidden commands that let the person read private details or alter pages on the website.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if the web server is set up to serve uploaded files based on their actual file type.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate Drupal Canvas to 1.4.2, 1.5.2, 1.6.1 or 1.7.1, whichever branch you are on.

For developers: what the fix changed

This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-066, the most serious of them.

The fix updates the file upload process in `CanvasBuilder.php` to use Drupal core's `FileUploadHandlerInterface` with the `FileIsImage` validator, ensuring the uploaded file is actually an image rather than relying on the client provided MIME type.

Also in this release The release also includes built assets for the Astro hydration package.

1.4.1 to 1.4.2 3 commits, 42 files.

  • .gitignore +2 −0
  • modules/canvas_ai/src/Controller/CanvasBuilder.php +31 −20 fix
  • packages/astro-hydration/dist/FormattedText-C1aZH-9n.js +1 −0
  • packages/astro-hydration/dist/FormattedText.js +1 −0
  • packages/astro-hydration/dist/Stub.js +2 −0
  • packages/astro-hydration/dist/_commonjsHelpers.js +1 −0
  • packages/astro-hydration/dist/astro.js +4 −0
  • packages/astro-hydration/dist/astro/server.js +0 −0
  • packages/astro-hydration/dist/canvas-island.js +1 −0
  • packages/astro-hydration/dist/class-variance-authority.js +1 −0
  • packages/astro-hydration/dist/client.js +1 −0
  • packages/astro-hydration/dist/clsx.js +1 −0

Full diff, 1.4.1 to 1.4.2 · Full diff, 1.5.1 to 1.5.2 · Full diff, 1.6.0 to 1.6.1 · Full diff, 1.7.0 to 1.7.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

FlowDrop

Moderately critical · 407 sites report using it · 2 security fixes

This module allows people to test and run artificial intelligence tasks through a chat screen.

2 security fixes in one update. FlowDrop fixed 2 separate security bugs this week: 2 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-068, is explained here and the full list is at the end of the card.

A person with an account could bypass approval steps when a task repeats. They could run tasks that were not approved and alter or view restricted data.

  • Who could do thisOnly someone with a login on your site.
  • Does it apply to youThis applies if a user has an access right to administer, create or edit FlowDrop workflows.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.

Tell your developerUpdate FlowDrop to 1.6.0.

For developers: what the fix changed

This release carries 2 security fixes. The summary below is for SA-CONTRIB-2026-068, the most serious of them.

Updates `InterruptResolvedSubscriber` and `SessionInterruptResolvedSubscriber` to dynamically resolve the correct pipeline executor rather than hardcoding the synchronous orchestrator, ensuring human-in-the-loop gates are properly re-evaluated when a workflow iterates (e.g. in stategraphs). It also reloads the pipeline entity after execution to prevent saving a stale state that could regress the pipeline's status.

Also in this release Added timing and scheduling nodes, a bulk dismiss feature for interrupts, and various UI improvements to the workflow editor and dashboard.

1.5.0 to 1.6.0 137 commits, 320 files including 54 tests.

  • .gitignore +9 −0
  • CHANGELOG.md +0 −0
  • composer.json +0 −1
  • docs/development/testing-node-processors.md +51 −0
  • docs/development/tool-aware-node-processors.md +407 −0
  • docs/guide/nodes/index.md +10 −0
  • docs/guide/nodes/timing.md +104 −0
  • docs/modules/flowdrop_stategraph.md +4 −4
  • docs/reference/api/rest-api.md +7 −0
  • docs/reference/api/session-turn-events.md +160 −0
  • docs/reference/architecture/proposal-dataflow-modeler-api.md +241 −0
  • mkdocs.yml +3 −0

Full diff, 1.5.0 to 1.6.0

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 2 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk

Compiled 10 October 2026 as part of the archive back to January 2026, from the advisories published by the Drupal security team on drupal.org. The facts on each card are theirs. The plain English is mine, with help from a language model. In the archive the cards rated critical or above were read before publishing and the rest were checked by sampling. Install counts are today's, not the count on the day of the advisory.


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.