AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Path Traversal In Chroma.Add_images() Via Unsanitized URI Allows Arbitrary File Read

Chroma.add_images() accepts arbitrary URI strings and passes them to encode_image(), which opens the file without path validation. An attacker who controls the URI can read any local file (e.g., /etc/passwd) and receive its base64-encoded content, leading to information disclosure.

highConfidence 95%Langchain-Chroma

Origin Analysis

The encode_image() method in langchain_chroma vectorstores uses Path(uri).open('rb') directly on user-supplied input. No check ensures the resolved path stays within an intended directory, enabling classic path traversal via sequences like ../../../../etc/passwd.
1. Install langchain-chroma and chromadb. 2. Create a Chroma store with embedding_function=None. 3. Call store.add_images(uris=['../../../../etc/passwd']). 4. Observe that the method reads the file and returns base64-encoded content without raising a ValueError.

Fixing Code Block

Edge Case Audit

This hotfix restricts image paths to the current working directory, which may break legitimate applications that pass absolute paths outside cwd. Consider adding a configurable base_dir parameter to add_images() and encode_image(). There is a TOCTOU race between validation and file opening; an attacker with filesystem write access could swap a symlink. Multi-threaded os.chdir() operations could change the meaning of 'cwd' during validation. Rollback: revert encode_image to its original form to restore previous behavior.

Ecosystem Topology