Mintplex-Labs/anything-llm · error
Invalid path name
Error message
Invalid path name
What it means
Thrown by POST /api/v1/document/create-folder when the requested folder name fails the containment check: after normalizePath(name) (which trims, strips leading ../ groups, and rejects exactly '..'/'.','.','/'), path.join(documentsPath, name) must still resolve strictly inside documentsPath per isWithin(). A name that smuggles a traversal (mid-string '..', absolute path, drive-relative segment on Windows) escapes and is rejected. The catch converts it to HTTP 500 'Failed to create folder: Invalid path name' — despite being a client-input problem.
Solutions
- Send a simple relative folder name with no '..', no leading slash, no drive letter — e.g. 'my-folder' or 'a/b'
- Sanitize client-side: strip path separators/parent segments or map them to '-' before POSTing
- If you need a nested path, create each level as its own relative name (a, then a/b)
- Treat the 500 'Invalid path name' as a 400-class signal: fix the name, nothing is wrong server-side
Example fix
// before
await fetch('/api/v1/document/create-folder', { method: 'POST', body: JSON.stringify({ name: 'reports/../../etc' }) });
// after
await fetch('/api/v1/document/create-folder', { method: 'POST', body: JSON.stringify({ name: 'reports/etc' }) }); Defensive patterns
Strategy: validation
Validate before calling
const path = require('path');
function safeFolderName(name) {
if (typeof name !== 'string' || !name.trim()) return null;
const cleaned = name.trim().replace(/[\\/]+/g, '-').replace(/\.\./g, '').replace(/^[.-]+/, '');
if (!cleaned || ['.', '..'].includes(cleaned)) return null;
return cleaned;
}
const name = safeFolderName(rawName);
if (!name) throw new Error('folder name must be a non-empty relative name'); Type guard
function isSafeFolderName(name: unknown): name is string {
return typeof name === 'string' && name.length > 0 && !name.includes('..') && !name.startsWith('/') && !/^[A-Za-z]:/.test(name) && !name.includes('\\');
} Try / catch
try { await api.post('/api/v1/document/create-folder', { name }); } catch (e) { if (/Invalid path name/.test(e.message)) { /* client-side bug: sanitize name per isSafeFolderName and re-send once */ } else throw e; } Prevention
- Treat 'Invalid path name' as a 400-class validation signal — never retry the same body
- Strip separators and '..' from user-supplied names before they reach the API
- Mirror the server rule in client validation: strictly relative, parent-free, single-name or safe relative path
When it happens
Trigger: POSTing name values like 'docs/../../escape', an absolute path '/etc/x' or 'C:\temp', '..foo/../..' patterns whose leading-strip leaves a remaining '../', or a name that resolves to documentsPath itself (isWithin returns false for rel === '').
Common situations: API clients building folder names from user input or file paths without sanitizing; tests using path-like names; legitimate requests for nested folders that accidentally include parent segments after normalization.
Understand the failure class
Background: Path traversal blocked: "path escapes the workspace" and "outside site root" errors when a path will not stay inside its allowed directory — this error's family across 26 libraries.
Related errors
- Invalid folder name.
- Could not find a document by id
- data.message || "Could not update slash command preset."
- data.message || "Error creating slash command preset."
- Failed to create folder
AI-assisted analysis of Mintplex-Labs/anything-llm@3aec848f28 (2026-08-18).
Data as JSON: /api/errors/17f901faf6341d31.
Report an issue: GitHub.
Appendix: source
Thrown at server/endpoints/api/document/index.js:941
example: {
success: true,
message: null
}
}
}
}
}
#swagger.responses[403] = {
schema: {
"$ref": "#/definitions/InvalidAPIKey"
}
}
*/
try {
const { name } = reqBody(request);
const storagePath = path.join(documentsPath, normalizePath(name));
if (!isWithin(path.resolve(documentsPath), path.resolve(storagePath)))
throw new Error("Invalid path name");
if (fs.existsSync(storagePath)) {
response.status(500).json({
success: false,
message: "Folder by that name already exists",
});
return;
}
fs.mkdirSync(storagePath, { recursive: true });
response.status(200).json({ success: true, message: null });
} catch (e) {
console.error(e);
response.status(500).json({
success: false,
message: `Failed to create folder: ${e.message}`,
});
}View on GitHub (pinned to 3aec848f28)