{"record":{"id":"97c4303bf334aec7","repo":"Mintplex-Labs/anything-llm","slug":"importedplugin-importcommunityitemfromurl-entry","errorCode":null,"errorMessage":"[ImportedPlugin.importCommunityItemFromUrl]: Entry \"${entry.entryName}\" would extract outside plugin folder - not allowed.","messagePattern":"\\[ImportedPlugin\\.importCommunityItemFromUrl\\]: Entry \"(.+?)\" would extract outside plugin folder - not allowed\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"server/utils/agents/imported.js","lineNumber":333,"sourceCode":"          );\n          resolve(false);\n        }\n      });\n\n      const success = await downloadZipFile;\n      if (!success)\n        return { success: false, error: \"Failed to download zip file.\" };\n\n      // Unzip the file to the plugin folder\n      // Note: https://github.com/cthackers/adm-zip?tab=readme-ov-file#electron-original-fs\n      const AdmZip = require(\"adm-zip\");\n      const zip = new AdmZip(zipFilePath);\n\n      // Validate all zip entries to prevent Zip Slip path traversal attacks (CWE-22)\n      for (const entry of zip.getEntries()) {\n        const entryPath = path.resolve(pluginFolder, entry.entryName);\n        if (!isWithin(pluginFolder, entryPath) && pluginFolder !== entryPath) {\n          throw new Error(\n            `[ImportedPlugin.importCommunityItemFromUrl]: Entry \"${entry.entryName}\" would extract outside plugin folder - not allowed.`\n          );\n        }\n      }\n\n      zip.extractAllTo(pluginFolder);\n\n      // We want to make sure specific keys are set to the proper values for\n      // plugin.json so we read and overwrite the file with the proper values.\n      const pluginJsonPath = path.resolve(pluginFolder, \"plugin.json\");\n      const pluginJson = safeJsonParse(fs.readFileSync(pluginJsonPath, \"utf8\"));\n      pluginJson.active = false;\n      pluginJson.hubId = hubId;\n      fs.writeFileSync(pluginJsonPath, JSON.stringify(pluginJson, null, 2));\n\n      console.log(\n        `ImportedPlugin.importCommunityItemFromUrl - successfully imported plugin to agent-skills/${hubId}`\n      );","sourceCodeStart":315,"sourceCodeEnd":351,"githubUrl":"https://github.com/Mintplex-Labs/anything-llm/blob/3aec848f2885144aa8f1e53b9731a04310d5d558/server/utils/agents/imported.js#L315-L351","documentation":"Zip-slip guard in ImportedPlugin.importCommunityItemFromUrl: a zip entry's resolved path would land outside the plugin folder (CWE-22 path traversal), so extraction of the downloaded community bundle is refused to prevent overwriting arbitrary files.","triggerScenarios":"A community plugin archive contains a path-traversal (zip slip) entry.","commonSituations":"This error is raised at runtime in server/utils/agents/imported.js. It occurs when the required configuration for this provider is missing or invalid (unset environment variables, empty API key or base path), when the external service is unreachable or returns an unexpected response, or when invalid input reaches the call site. To prevent it, validate the relevant provider settings and environment variables at startup and confirm the service is reachable before this code path executes.","solutions":["Do not import this archive; it contains entries that would extract outside the plugin folder.","Repackage the plugin with safe relative paths."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3aec848f2885144aa8f1e53b9731a04310d5d558","analyzedAt":"2026-08-18T10:02:21.017Z","contentChangedAt":"2026-08-18T10:02:21.017Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}