What happened?
On Windows with the local file storage strategy, deleting any image file stored under /images// fails with a TypeError. Uploaded images, generated images and agent avatars can therefore never be deleted; the file and its DB record remain.
Cause: api/server/services/Files/Local/crud.js stores file paths with path.posix.join (forward slashes, line 95) but splits them again with path.sep when deleting (lines 258-259). On Windows path.sep is a backslash, so the split yields a single element, subfolder is undefined, and isValidPath(req, publicPath, undefined, filepath) calls path.resolve(base, undefined, ...) which throws "The paths[1] argument must be of type string" (line 201). Files under /uploads// are unaffected because that branch returns earlier.
The call chain is the normal UI deletion path: routes/files/files.js:277 -> processDeleteRequest (services/Files/process.js:325) -> deleteLocalFile (crud.js:266) -> isValidPath (crud.js:201).
Side effect: the client keeps failed deletions in localStorage (FILES_TO_DELETE) and retries them on every mount of the chat view (client/src/components/Chat/Presentation.tsx:81-100), so the error log fills with one DELETE /api/files per minute while a user has such files pending.
On Linux path.sep is "/", so the bug never shows there.
Suggested fix: split on "/" instead of path.sep in crud.js:258, consistent with how the same file builds the path. No behaviour change on Linux.
Our instance: 137 file records, 65 of them images under /images/ that cannot be deleted; 96 failed DELETE /api/files requests from a single session within 72 minutes.
Version Information
LibreChat v0.8.8-rc3, Windows Server (native, no Docker), fileStrategy: local. The code is unchanged in v0.8.8-rc4 (crud.js:269-270).
Steps to Reproduce
- Run LibreChat natively on Windows with the local file strategy.
- Upload an image in a chat or set an agent avatar.
- Delete the image (or the conversation) in the UI.
- Observe in the error log: DELETE /api/files fails with "The paths[1] argument must be of type string" at services/Files/Local/crud.js:201; the file and DB record remain.
- Reload the chat view: the DELETE is retried and fails again.
What browsers are you seeing the problem on?
Microsoft Edge
Relevant log output
{
"code": "ERR_INVALID_ARG_TYPE",
"level": "error",
"message": "The \"paths[1]\" argument must be of type string. Received undefined",
"name": "TypeError",
"requestId": "<requestId>",
"request_id": "<requestId>",
"request_method": "DELETE",
"request_path": "/api/files",
"stack": "TypeError [ERR_INVALID_ARG_TYPE]: The \"paths[1]\" argument must be of type string. Received undefined\n at isValidPath (api/server/services/Files/Local/crud.js:201:31)\n at deleteLocalFile (api/server/services/Files/Local/crud.js:266:8)\n at async api/server/services/Files/process.js:205:7\n at async processDeleteRequest (api/server/services/Files/process.js:325:3)\n at async api/server/routes/files/files.js:277:22",
"timestamp": "2026-09-23T23:51:16.560Z",
"userId": "<userId>"
}
Screenshots
No response
Code of Conduct
What happened?
On Windows with the local file storage strategy, deleting any image file stored under /images// fails with a TypeError. Uploaded images, generated images and agent avatars can therefore never be deleted; the file and its DB record remain.
Cause: api/server/services/Files/Local/crud.js stores file paths with path.posix.join (forward slashes, line 95) but splits them again with path.sep when deleting (lines 258-259). On Windows path.sep is a backslash, so the split yields a single element, subfolder is undefined, and isValidPath(req, publicPath, undefined, filepath) calls path.resolve(base, undefined, ...) which throws "The paths[1] argument must be of type string" (line 201). Files under /uploads// are unaffected because that branch returns earlier.
The call chain is the normal UI deletion path: routes/files/files.js:277 -> processDeleteRequest (services/Files/process.js:325) -> deleteLocalFile (crud.js:266) -> isValidPath (crud.js:201).
Side effect: the client keeps failed deletions in localStorage (FILES_TO_DELETE) and retries them on every mount of the chat view (client/src/components/Chat/Presentation.tsx:81-100), so the error log fills with one DELETE /api/files per minute while a user has such files pending.
On Linux path.sep is "/", so the bug never shows there.
Suggested fix: split on "/" instead of path.sep in crud.js:258, consistent with how the same file builds the path. No behaviour change on Linux.
Our instance: 137 file records, 65 of them images under /images/ that cannot be deleted; 96 failed DELETE /api/files requests from a single session within 72 minutes.
Version Information
LibreChat v0.8.8-rc3, Windows Server (native, no Docker), fileStrategy: local. The code is unchanged in v0.8.8-rc4 (crud.js:269-270).
Steps to Reproduce
What browsers are you seeing the problem on?
Microsoft Edge
Relevant log output
{ "code": "ERR_INVALID_ARG_TYPE", "level": "error", "message": "The \"paths[1]\" argument must be of type string. Received undefined", "name": "TypeError", "requestId": "<requestId>", "request_id": "<requestId>", "request_method": "DELETE", "request_path": "/api/files", "stack": "TypeError [ERR_INVALID_ARG_TYPE]: The \"paths[1]\" argument must be of type string. Received undefined\n at isValidPath (api/server/services/Files/Local/crud.js:201:31)\n at deleteLocalFile (api/server/services/Files/Local/crud.js:266:8)\n at async api/server/services/Files/process.js:205:7\n at async processDeleteRequest (api/server/services/Files/process.js:325:3)\n at async api/server/routes/files/files.js:277:22", "timestamp": "2026-09-23T23:51:16.560Z", "userId": "<userId>" }Screenshots
No response
Code of Conduct