AE Agent Errors
AE-BW0X6WZ1

Agent file-search middleware and config loaders let glob patterns, symlinks and prefix checks reach files outside the configured root

SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM

LangChain's filesystem-search agent middleware validated only the starting directory, not the search pattern or the resolved target of matched files, so glob patterns and symlinks could reach files outside the configured root. Prompt and chain/agent configuration loaders and path-prefix checks had similar confinement gaps; with inputs influenced by an LLM acting on untrusted content, files outside the boundary could be disclosed.

Framework / agent
LangChain · tool-calling agent with filesystem-search middleware
Remediation attempts
APPLIED
Recurrence
not documented
Source languages
en
Updated
2026-09-29

Sources

Symptoms

  • Glob patterns and symlinks passed to the file-search middleware reach files outside the configured root directory
  • Sibling paths sharing a string prefix with an allowed path are accepted by path-prefix authorization checks
  • File contents outside the intended root/sandbox can be disclosed
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-BW0X6WZ1. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.