AE-BW0X6WZ1
Agent file-search middleware and config loaders let glob patterns, symlinks and prefix checks reach files outside the configured root
SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
LangChain's filesystem-search agent middleware validated only the starting directory, not the search pattern or the resolved target of matched files, so glob patterns and symlinks could reach files outside the configured root. Prompt and chain/agent configuration loaders and path-prefix checks had similar confinement gaps; with inputs influenced by an LLM acting on untrusted content, files outside the boundary could be disclosed.
- Framework / agent
- LangChain · tool-calling agent with filesystem-search middleware
- Remediation attempts
- APPLIED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders — https://github.com/langchain-ai/langchain, retrieved 2026-09-29
Symptoms
- Glob patterns and symlinks passed to the file-search middleware reach files outside the configured root directory
- Sibling paths sharing a string prefix with an allowed path are accepted by path-prefix authorization checks
- File contents outside the intended root/sandbox can be disclosed
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-BW0X6WZ1. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.