Mintplex-Labs/anything-llm · error · Error

[ImportedPlugin.importCommunityItemFromUrl]: Entry

Error message

[ImportedPlugin.importCommunityItemFromUrl]: Entry "${entry.entryName}" would extract outside plugin folder - not allowed.

What it means

Zip-slip guard in ImportedPlugin.importCommunityItemFromUrl: a zip entry's resolved path would land outside the plugin folder (CWE-22 path traversal), so extraction of the downloaded community bundle is refused to prevent overwriting arbitrary files.

Solutions

  1. Do not import this archive; it contains entries that would extract outside the plugin folder.
  2. Repackage the plugin with safe relative paths.
Defensive patterns

Strategy: validation

When it happens

Trigger: A community plugin archive contains a path-traversal (zip slip) entry.

Common situations: This error is raised at runtime in server/utils/agents/imported.js. It occurs when the required configuration for this provider is missing or invalid (unset environment variables, empty API key or base path), when the external service is unreachable or returns an unexpected response, or when invalid input reaches the call site. To prevent it, validate the relevant provider settings and environment variables at startup and confirm the service is reachable before this code path executes.


AI-assisted analysis of Mintplex-Labs/anything-llm@3aec848f28 (2026-08-18). Data as JSON: /api/errors/97c4303bf334aec7. Report an issue: GitHub.

Appendix: source

Thrown at server/utils/agents/imported.js:333

          );
          resolve(false);
        }
      });

      const success = await downloadZipFile;
      if (!success)
        return { success: false, error: "Failed to download zip file." };

      // Unzip the file to the plugin folder
      // Note: https://github.com/cthackers/adm-zip?tab=readme-ov-file#electron-original-fs
      const AdmZip = require("adm-zip");
      const zip = new AdmZip(zipFilePath);

      // Validate all zip entries to prevent Zip Slip path traversal attacks (CWE-22)
      for (const entry of zip.getEntries()) {
        const entryPath = path.resolve(pluginFolder, entry.entryName);
        if (!isWithin(pluginFolder, entryPath) && pluginFolder !== entryPath) {
          throw new Error(
            `[ImportedPlugin.importCommunityItemFromUrl]: Entry "${entry.entryName}" would extract outside plugin folder - not allowed.`
          );
        }
      }

      zip.extractAllTo(pluginFolder);

      // We want to make sure specific keys are set to the proper values for
      // plugin.json so we read and overwrite the file with the proper values.
      const pluginJsonPath = path.resolve(pluginFolder, "plugin.json");
      const pluginJson = safeJsonParse(fs.readFileSync(pluginJsonPath, "utf8"));
      pluginJson.active = false;
      pluginJson.hubId = hubId;
      fs.writeFileSync(pluginJsonPath, JSON.stringify(pluginJson, null, 2));

      console.log(
        `ImportedPlugin.importCommunityItemFromUrl - successfully imported plugin to agent-skills/${hubId}`
      );

View on GitHub (pinned to 3aec848f28)