AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

File_search Fallback: Unbounded Regex Execution When Ripgrep Is Absent (ReDoS)

When ripgrep is not installed, FilesystemFileSearchMiddleware falls back to in-process Python regex search on model-controlled patterns, leading to catastrophic backtracking and denial of service.

highConfidence 95%Langchain

Origin Analysis

The fallback _python_search method compiles and executes the model-provided regex pattern in-process without a timeout, unlike the ripgrep path which has a 30-second subprocess timeout. This allows adversarial regex patterns like ([0-9a-f]+)+g to cause exponential backtracking on long hex strings.
1. Install langchain v1 without ripgrep. 2. Create a temporary directory with a file containing a long hex string (e.g. 'sha256:' + 40 hex chars). 3. Instantiate FilesystemFileSearchMiddleware with use_ripgrep=False. 4. Call _python_search('([0-9a-f]+)+g', tmp_path, None) and observe the hang.

Fixing Code Block

Edge Case Audit

The subprocess-based fallback adds process spawn overhead for every search, which may degrade performance under high frequency or large directory trees. The 30-second timeout may cause legitimate long-running searches to be incorrectly aborted, returning empty results; ensure this is acceptable. The inline script uses JSON for result serialization, which can fail or be slow for extremely large result sets (many matched files), potentially causing false negatives. The subprocess approach may be less reliable on systems where Python interpreter is not accessible via sys.executable (e.g., frozen executables) or where subprocess spawning is restricted. Rollback: revert to the original in-process search if performance issues or compatibility problems arise in specific environments; consider adding a timeout via signal/alarm only as a last resort on Unix.

Ecosystem Topology