{"record":{"id":"0764b21678cdaaae","repo":"Mintplex-Labs/anything-llm","slug":"plugin-handler-does-not-pass-path-validation","errorCode":null,"errorMessage":"Plugin handler does not pass path validation.","messagePattern":"Plugin handler does not pass path validation\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"server/utils/agents/imported.js","lineNumber":21,"sourceCode":"const { safeJsonParse } = require(\"../http\");\nconst { isWithin, normalizePath } = require(\"../files\");\nconst { CollectorApi } = require(\"../collectorApi\");\nconst pluginsPath =\n  process.env.NODE_ENV === \"development\"\n    ? path.resolve(__dirname, \"../../storage/plugins/agent-skills\")\n    : path.resolve(process.env.STORAGE_DIR, \"plugins\", \"agent-skills\");\nconst sharedWebScraper = new CollectorApi();\n\nclass ImportedPlugin {\n  constructor(config) {\n    this.config = config;\n    this.handlerLocation = path.resolve(\n      pluginsPath,\n      normalizePath(this.config.hubId),\n      \"handler.js\"\n    );\n    if (!isWithin(pluginsPath, this.handlerLocation))\n      throw new Error(\"Plugin handler does not pass path validation.\");\n    delete require.cache[require.resolve(this.handlerLocation)];\n    this.handler = require(this.handlerLocation);\n    this.name = config.hubId;\n    this.startupConfig = {\n      params: {},\n    };\n  }\n\n  /**\n   * Gets the imported plugin handler.\n   * @param {string} hubId - The hub ID of the plugin.\n   * @returns {ImportedPlugin} - The plugin handler.\n   */\n  static loadPluginByHubId(hubId) {\n    const configLocation = path.resolve(\n      pluginsPath,\n      normalizePath(hubId),\n      \"plugin.json\"","sourceCodeStart":3,"sourceCodeEnd":39,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/3aec848f2885144aa8f1e53b9731a04310d5d558/server/utils/agents/imported.js#L3-L39","documentation":"Security guard in ImportedPlugin constructor: the resolved plugin handler path fails the isWithin check against the plugins root, meaning the hubId-derived path would escape the designated agent-skills directory (path traversal attempt) and is rejected.","triggerScenarios":"An imported agent plugin handler failed path validation.","commonSituations":"This error is raised at runtime in server/utils/agents/imported.js. It occurs when the required configuration for this provider is missing or invalid (unset environment variables, empty API key or base path), when the external service is unreachable or returns an unexpected response, or when invalid input reaches the call site. To prevent it, validate the relevant provider settings and environment variables at startup and confirm the service is reachable before this code path executes.","solutions":["Fix the imported plugin so its handler only accesses paths inside the allowed directories.","Remove or replace the untrusted plugin."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3aec848f2885144aa8f1e53b9731a04310d5d558","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}