Mintplex-Labs/anything-llm · error · Error

Invalid path.

Error message

Invalid path.

What it means

Sanitization guard in normalizePath: after trimming and stripping traversal prefixes, the path resolves to a pure relative anchor ('..', '.', or '/'), meaning the supplied filepath denotes no concrete file location and would be unsafe to join, so it is rejected.

Solutions

  1. Provide a valid, normalized path inside the allowed documents directory.
  2. Remove path traversal segments from the supplied path.
Defensive patterns

Strategy: validation

When it happens

Trigger: A file operation received an invalid or unsafe path.

Common situations: This error is raised at runtime in server/utils/files/index.js. It occurs when the required configuration for this provider is missing or invalid (unset environment variables, empty API key or base path), when the external service is unreachable or returns an unexpected response, or when invalid input reaches the call site. To prevent it, validate the relevant provider settings and environment variables at startup and confirm the service is reachable before this code path executes.


AI-assisted analysis of Mintplex-Labs/anything-llm@f92433b4ea (2026-08-18). Data as JSON: /api/errors/792e4bcf6b1a4a81. Report an issue: GitHub.

Appendix: source

Thrown at server/utils/files/index.js:394

 * @returns {boolean} True if `inner` is strictly inside `outer`, false otherwise.
 */
function isWithin(outer, inner) {
  const resolvedOuter = path.resolve(outer);
  const resolvedInner = path.resolve(inner);
  const rel = path.relative(resolvedOuter, resolvedInner);

  if (rel === "") return false;
  return (
    !rel.startsWith(`..${path.sep}`) && rel !== ".." && !path.isAbsolute(rel)
  );
}

function normalizePath(filepath = "") {
  const result = path
    .normalize(filepath.trim())
    .replace(/^(\.\.(\/|\\|$))+/, "")
    .trim();
  if (["..", ".", "/"].includes(result)) throw new Error("Invalid path.");
  return result;
}

/**
 * Strips characters that are illegal in Windows filenames, including Unicode
 * quotation marks (U+201C, U+201D, etc.) that can get corrupted into ASCII
 * double-quotes during charset conversion in the upload pipeline.
 * @param {string} fileName - The filename to sanitize.
 * @returns {string} - The sanitized filename.
 */
function sanitizeFileName(fileName) {
  if (!fileName) return fileName;
  return fileName.replace(
    /[<>:"/\\|?*\u201C\u201D\u201E\u201F\u2018\u2019\u201A\u201B]/g,
    ""
  );
}

View on GitHub (pinned to f92433b4ea)