Mintplex-Labs/anything-llm · error · Error
Plugin handler does not pass path validation.
Error message
Plugin handler does not pass path validation.
What it means
Security guard in ImportedPlugin constructor: the resolved plugin handler path fails the isWithin check against the plugins root, meaning the hubId-derived path would escape the designated agent-skills directory (path traversal attempt) and is rejected.
Solutions
- Fix the imported plugin so its handler only accesses paths inside the allowed directories.
- Remove or replace the untrusted plugin.
Defensive patterns
Strategy: validation
When it happens
Trigger: An imported agent plugin handler failed path validation.
Common situations: This error is raised at runtime in server/utils/agents/imported.js. It occurs when the required configuration for this provider is missing or invalid (unset environment variables, empty API key or base path), when the external service is unreachable or returns an unexpected response, or when invalid input reaches the call site. To prevent it, validate the relevant provider settings and environment variables at startup and confirm the service is reachable before this code path executes.
AI-assisted analysis of Mintplex-Labs/anything-llm@3aec848f28 (2026-08-18).
Data as JSON: /api/errors/0764b21678cdaaae.
Report an issue: GitHub.
Appendix: source
Thrown at server/utils/agents/imported.js:21
const { safeJsonParse } = require("../http");
const { isWithin, normalizePath } = require("../files");
const { CollectorApi } = require("../collectorApi");
const pluginsPath =
process.env.NODE_ENV === "development"
? path.resolve(__dirname, "../../storage/plugins/agent-skills")
: path.resolve(process.env.STORAGE_DIR, "plugins", "agent-skills");
const sharedWebScraper = new CollectorApi();
class ImportedPlugin {
constructor(config) {
this.config = config;
this.handlerLocation = path.resolve(
pluginsPath,
normalizePath(this.config.hubId),
"handler.js"
);
if (!isWithin(pluginsPath, this.handlerLocation))
throw new Error("Plugin handler does not pass path validation.");
delete require.cache[require.resolve(this.handlerLocation)];
this.handler = require(this.handlerLocation);
this.name = config.hubId;
this.startupConfig = {
params: {},
};
}
/**
* Gets the imported plugin handler.
* @param {string} hubId - The hub ID of the plugin.
* @returns {ImportedPlugin} - The plugin handler.
*/
static loadPluginByHubId(hubId) {
const configLocation = path.resolve(
pluginsPath,
normalizePath(hubId),
"plugin.json"View on GitHub (pinned to 3aec848f28)