{"record":{"id":"17f901faf6341d31","repo":"Mintplex-Labs/anything-llm","slug":"invalid-path-name","errorCode":null,"errorMessage":"Invalid path name","messagePattern":"Invalid path name","errorType":"http","errorClass":null,"httpStatus":500,"severity":"error","filePath":"server/endpoints/api/document/index.js","lineNumber":941,"sourceCode":"              example: {\n                success: true,\n                message: null\n              }\n            }\n          }\n        }\n      }\n      #swagger.responses[403] = {\n        schema: {\n          \"$ref\": \"#/definitions/InvalidAPIKey\"\n        }\n      }\n      */\n      try {\n        const { name } = reqBody(request);\n        const storagePath = path.join(documentsPath, normalizePath(name));\n        if (!isWithin(path.resolve(documentsPath), path.resolve(storagePath)))\n          throw new Error(\"Invalid path name\");\n\n        if (fs.existsSync(storagePath)) {\n          response.status(500).json({\n            success: false,\n            message: \"Folder by that name already exists\",\n          });\n          return;\n        }\n\n        fs.mkdirSync(storagePath, { recursive: true });\n        response.status(200).json({ success: true, message: null });\n      } catch (e) {\n        console.error(e);\n        response.status(500).json({\n          success: false,\n          message: `Failed to create folder: ${e.message}`,\n        });\n      }","sourceCodeStart":923,"sourceCodeEnd":959,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/3aec848f2885144aa8f1e53b9731a04310d5d558/server/endpoints/api/document/index.js#L923-L959","documentation":"Thrown by POST /api/v1/document/create-folder when the requested folder name fails the containment check: after normalizePath(name) (which trims, strips leading ../ groups, and rejects exactly '..'/'.','.','/'), path.join(documentsPath, name) must still resolve strictly inside documentsPath per isWithin(). A name that smuggles a traversal (mid-string '..', absolute path, drive-relative segment on Windows) escapes and is rejected. The catch converts it to HTTP 500 'Failed to create folder: Invalid path name' — despite being a client-input problem.","triggerScenarios":"POSTing name values like 'docs/../../escape', an absolute path '/etc/x' or 'C:\\temp', '..foo/../..' patterns whose leading-strip leaves a remaining '../', or a name that resolves to documentsPath itself (isWithin returns false for rel === '').","commonSituations":"API clients building folder names from user input or file paths without sanitizing; tests using path-like names; legitimate requests for nested folders that accidentally include parent segments after normalization.","solutions":["Send a simple relative folder name with no '..', no leading slash, no drive letter — e.g. 'my-folder' or 'a/b'","Sanitize client-side: strip path separators/parent segments or map them to '-' before POSTing","If you need a nested path, create each level as its own relative name (a, then a/b)","Treat the 500 'Invalid path name' as a 400-class signal: fix the name, nothing is wrong server-side"],"exampleFix":"// before\nawait fetch('/api/v1/document/create-folder', { method: 'POST', body: JSON.stringify({ name: 'reports/../../etc' }) });\n// after\nawait fetch('/api/v1/document/create-folder', { method: 'POST', body: JSON.stringify({ name: 'reports/etc' }) });","handlingStrategy":"validation","validationCode":"const path = require('path');\nfunction safeFolderName(name) {\n  if (typeof name !== 'string' || !name.trim()) return null;\n  const cleaned = name.trim().replace(/[\\\\/]+/g, '-').replace(/\\.\\./g, '').replace(/^[.-]+/, '');\n  if (!cleaned || ['.', '..'].includes(cleaned)) return null;\n  return cleaned;\n}\nconst name = safeFolderName(rawName);\nif (!name) throw new Error('folder name must be a non-empty relative name');","typeGuard":"function isSafeFolderName(name: unknown): name is string {\n  return typeof name === 'string' && name.length > 0 && !name.includes('..') && !name.startsWith('/') && !/^[A-Za-z]:/.test(name) && !name.includes('\\\\');\n}","tryCatchPattern":"try { await api.post('/api/v1/document/create-folder', { name }); } catch (e) { if (/Invalid path name/.test(e.message)) { /* client-side bug: sanitize name per isSafeFolderName and re-send once */ } else throw e; }","preventionTips":["Treat 'Invalid path name' as a 400-class validation signal — never retry the same body","Strip separators and '..' from user-supplied names before they reach the API","Mirror the server rule in client validation: strictly relative, parent-free, single-name or safe relative path"],"tags":["anythingllm","documents","folder-creation","path-traversal","api","validation"],"backgroundTag":"path-traversal-blocked","analyzedSha":"3aec848f2885144aa8f1e53b9731a04310d5d558","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}