influxdata/influxdb · error · PluginError
Path traversal detected: plugin filename
Error message
Path traversal detected: plugin filename '{0}' attempts to access files outside the plugin directory What it means
PluginError::PathTraversal is thrown when a requested plugin filename escapes the configured plugin directory (contains '..' segments or absolute paths), a security guard against arbitrary file reads/writes via the plugin API.
Solutions
- Pass only a bare filename with no path separators or '..' segments.
- Sanitize/normalize the name (keep alphanumerics, dot, underscore, hyphen) before calling the API.
- Place required files inside the plugin directory and reference them by name only.
Example fix
// before
client.install_plugin("../../etc/passwd")
// after
client.install_plugin("my_plugin.py") Defensive patterns
Strategy: validation
Validate before calling
fn is_safe_plugin_name(name: &str) -> bool {
!name.is_empty()
&& !name.contains(['/', '\\'])
&& !name.contains("..")
&& name.chars().all(|c| c.is_ascii_alphanumeric() || matches!(c, '.' | '_' | '-'))
} Type guard
fn is_bare_filename(name: &str) -> bool { name == std::path::Path::new(name).file_name().and_then(|s| s.to_str()).unwrap_or("") } Prevention
- Never build plugin names from untrusted user input.
- Whitelist filenames against the plugin directory listing.
- Treat any path-separator in a plugin name as an error in callers.
When it happens
Trigger: Requesting a plugin whose filename resolves outside the plugin dir, e.g. '../../etc/passwd' or '/etc/cron.d/evil' passed to the install/lookup API.
Common situations: Malicious or mistaken API calls using relative paths; automation scripts constructing filenames from untrusted input; copy-pasted paths with directory components.
Understand the failure class
Background: Path traversal blocked: "path escapes the workspace" and "outside site root" errors when a path will not stay inside its allowed directory — this error's family across 26 libraries.
Related errors
- database not found for trigger
- Failed to import plugin module
- Node not configured with plugin directory
- Plugin error
- Python environment initialization failed
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/e2e7e00e3d825473.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_processing_engine/src/plugins.rs:79
#[error("non-schedule plugin with schedule trigger: {0}")]
NonSchedulePluginWithScheduleTrigger(String),
#[error("error fetching plugin from repository: {0} {1}")]
FetchingFromRepository(reqwest::StatusCode, String),
#[error(
"plugin installation is disabled; plugins must already exist in the configured plugin directory"
)]
PluginInstallationDisabled,
#[error("Join error, please report: {0}")]
JoinError(#[from] tokio::task::JoinError),
#[error("Node not configured with plugin directory")]
NoPluginDir,
#[error(
"Path traversal detected: plugin filename '{0}' attempts to access files outside the plugin directory"
)]
PathTraversal(String),
}
#[derive(Debug, Clone)]
pub struct ProcessingEngineEnvironmentManager {
pub plugin_dir: Option<PathBuf>,
pub virtual_env_location: Option<PathBuf>,
pub package_manager: Arc<dyn PythonEnvironmentManager>,
pub plugin_dir_only: bool,
pub plugin_repo: Option<String>,
}
pub(crate) fn run_schedule_event_source(
trigger_definition: Arc<TriggerDefinition>,
time_provider: Arc<dyn TimeProvider>,
scheduler: Scheduler,View on GitHub (pinned to 06200ef96b)