FlowDrop
2 security fixes in one update. FlowDrop fixed 2 separate security bugs this week: 2 access bypass. One update covers all of them. The most serious, SA-CONTRIB-2026-068, is explained here and the full list is at the end of the card.
A person with an account could bypass approval steps when a task repeats. They could run tasks that were not approved and alter or view restricted data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if a user has an access right to administer, create or edit FlowDrop workflows.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate FlowDrop to 1.6.0.
For developers: what the fix changed
Updates `InterruptResolvedSubscriber` and `SessionInterruptResolvedSubscriber` to dynamically resolve the correct pipeline executor rather than hardcoding the synchronous orchestrator, ensuring human-in-the-loop gates are properly re-evaluated when a workflow iterates (e.g. in stategraphs). It also reloads the pipeline entity after execution to prevent saving a stale state that could regress the pipeline's status.
Also in this release Added timing and scheduling nodes, a bulk dismiss feature for interrupts, and various UI improvements to the workflow editor and dashboard.
.gitignore+9 −0CHANGELOG.md+0 −0composer.json+0 −1docs/development/testing-node-processors.md+51 −0docs/development/tool-aware-node-processors.md+407 −0docs/guide/nodes/index.md+10 −0docs/guide/nodes/timing.md+104 −0docs/modules/flowdrop_stategraph.md+4 −4docs/reference/api/rest-api.md+7 −0docs/reference/api/session-turn-events.md+160 −0docs/reference/architecture/proposal-dataflow-modeler-api.md+241 −0mkdocs.yml+3 −0
- Moderately critical · Access bypass · SA-CONTRIB-2026-068
- Moderately critical · Access bypass · SA-CONTRIB-2026-067