Mintplex-Labs/anything-llm · error

Invalid path name

Error message

Invalid path name

What it means

Thrown by POST /api/v1/document/create-folder when the requested folder name fails the containment check: after normalizePath(name) (which trims, strips leading ../ groups, and rejects exactly '..'/'.','.','/'), path.join(documentsPath, name) must still resolve strictly inside documentsPath per isWithin(). A name that smuggles a traversal (mid-string '..', absolute path, drive-relative segment on Windows) escapes and is rejected. The catch converts it to HTTP 500 'Failed to create folder: Invalid path name' — despite being a client-input problem.

Solutions

  1. Send a simple relative folder name with no '..', no leading slash, no drive letter — e.g. 'my-folder' or 'a/b'
  2. Sanitize client-side: strip path separators/parent segments or map them to '-' before POSTing
  3. If you need a nested path, create each level as its own relative name (a, then a/b)
  4. Treat the 500 'Invalid path name' as a 400-class signal: fix the name, nothing is wrong server-side

Example fix

// before
await fetch('/api/v1/document/create-folder', { method: 'POST', body: JSON.stringify({ name: 'reports/../../etc' }) });
// after
await fetch('/api/v1/document/create-folder', { method: 'POST', body: JSON.stringify({ name: 'reports/etc' }) });
Defensive patterns

Strategy: validation

Validate before calling

const path = require('path');
function safeFolderName(name) {
  if (typeof name !== 'string' || !name.trim()) return null;
  const cleaned = name.trim().replace(/[\\/]+/g, '-').replace(/\.\./g, '').replace(/^[.-]+/, '');
  if (!cleaned || ['.', '..'].includes(cleaned)) return null;
  return cleaned;
}
const name = safeFolderName(rawName);
if (!name) throw new Error('folder name must be a non-empty relative name');

Type guard

function isSafeFolderName(name: unknown): name is string {
  return typeof name === 'string' && name.length > 0 && !name.includes('..') && !name.startsWith('/') && !/^[A-Za-z]:/.test(name) && !name.includes('\\');
}

Try / catch

try { await api.post('/api/v1/document/create-folder', { name }); } catch (e) { if (/Invalid path name/.test(e.message)) { /* client-side bug: sanitize name per isSafeFolderName and re-send once */ } else throw e; }

Prevention

When it happens

Trigger: POSTing name values like 'docs/../../escape', an absolute path '/etc/x' or 'C:\temp', '..foo/../..' patterns whose leading-strip leaves a remaining '../', or a name that resolves to documentsPath itself (isWithin returns false for rel === '').

Common situations: API clients building folder names from user input or file paths without sanitizing; tests using path-like names; legitimate requests for nested folders that accidentally include parent segments after normalization.

Understand the failure class

Background: Path traversal blocked: "path escapes the workspace" and "outside site root" errors when a path will not stay inside its allowed directory — this error's family across 26 libraries.

Related errors


AI-assisted analysis of Mintplex-Labs/anything-llm@3aec848f28 (2026-08-18). Data as JSON: /api/errors/17f901faf6341d31. Report an issue: GitHub.

Appendix: source

Thrown at server/endpoints/api/document/index.js:941

              example: {
                success: true,
                message: null
              }
            }
          }
        }
      }
      #swagger.responses[403] = {
        schema: {
          "$ref": "#/definitions/InvalidAPIKey"
        }
      }
      */
      try {
        const { name } = reqBody(request);
        const storagePath = path.join(documentsPath, normalizePath(name));
        if (!isWithin(path.resolve(documentsPath), path.resolve(storagePath)))
          throw new Error("Invalid path name");

        if (fs.existsSync(storagePath)) {
          response.status(500).json({
            success: false,
            message: "Folder by that name already exists",
          });
          return;
        }

        fs.mkdirSync(storagePath, { recursive: true });
        response.status(200).json({ success: true, message: null });
      } catch (e) {
        console.error(e);
        response.status(500).json({
          success: false,
          message: `Failed to create folder: ${e.message}`,
        });
      }

View on GitHub (pinned to 3aec848f28)