GHunter: Universal Prototype Pollution Gadgets in JavaScript Runtimes
Fuente:
arXiv
Saved in:
| Main Authors: | Cornelissen, Eric, Shcherbakov, Mikhail, Balliu, Musard |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js
by: Cornelissen, Eric, et al.
Published: (2025)
by: Cornelissen, Eric, et al.
Published: (2025)
Granite: Granular Runtime Enforcement for GitHub Actions Permissions
by: Moazen, Mojtaba, et al.
Published: (2025)
by: Moazen, Mojtaba, et al.
Published: (2025)
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026)
by: Zhang, Lingming, et al.
Published: (2026)
Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
by: Ali, Mir Masood, et al.
Published: (2024)
by: Ali, Mir Masood, et al.
Published: (2024)
Blocking Tracking JavaScript at the Function Granularity
by: Amjad, Abdul Haddi, et al.
Published: (2024)
by: Amjad, Abdul Haddi, et al.
Published: (2024)
Characterizing Phishing Pages by JavaScript Capabilities
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
by: Nahapetyan, Aleksandr, et al.
Published: (2025)
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
by: Sorger, Tom, et al.
Published: (2026)
by: Sorger, Tom, et al.
Published: (2026)
Sharing without Showing: Secure Cloud Analytics with Trusted Execution Environments
by: Birgersson, Marcus, et al.
Published: (2024)
by: Birgersson, Marcus, et al.
Published: (2024)
Disjunctive Policies for Database-Backed Programs
by: Ahmadian, Amir M., et al.
Published: (2023)
by: Ahmadian, Amir M., et al.
Published: (2023)
Obfuscating Code Vulnerabilities against Static Analysis in JavaScript Code
by: Pagano, Francesco, et al.
Published: (2026)
by: Pagano, Francesco, et al.
Published: (2026)
An Empirical Study of JavaScript Inclusion Security Issues in Chrome Extensions
by: Guan, Chong
Published: (2025)
by: Guan, Chong
Published: (2025)
Enhancing JavaScript Malware Detection through Weighted Behavioral DFAs
by: Pereira, Pedro, et al.
Published: (2025)
by: Pereira, Pedro, et al.
Published: (2025)
PatchFuzz: Patch Fuzzing for JavaScript Engines
by: Wang, Junjie, et al.
Published: (2025)
by: Wang, Junjie, et al.
Published: (2025)
JsDeObsBench: Measuring and Benchmarking LLMs for JavaScript Deobfuscation
by: Chen, Guoqiang, et al.
Published: (2025)
by: Chen, Guoqiang, et al.
Published: (2025)
FV8: A Forced Execution JavaScript Engine for Detecting Evasive Techniques
by: Pantelaios, Nikolaos, et al.
Published: (2024)
by: Pantelaios, Nikolaos, et al.
Published: (2024)
Original Sin of npm: A Study on Vulnerability Propagation in JavaScript Dependency Networks
by: Robinson, Michael, et al.
Published: (2026)
by: Robinson, Michael, et al.
Published: (2026)
Challenging Machine Learning Algorithms in Predicting Vulnerable JavaScript Functions
by: Ferenc, Rudolf, et al.
Published: (2024)
by: Ferenc, Rudolf, et al.
Published: (2024)
Fakeium: A Dynamic Execution Environment for JavaScript Program Analysis
by: Moreno, José Miguel, et al.
Published: (2024)
by: Moreno, José Miguel, et al.
Published: (2024)
A Study of Vulnerability Repair in JavaScript Programs with Large Language Models
by: Le, Tan Khang, et al.
Published: (2024)
by: Le, Tan Khang, et al.
Published: (2024)
Static Semantics Reconstruction for Enhancing JavaScript-WebAssembly Multilingual Malware Detection
by: Xia, Yifan, et al.
Published: (2023)
by: Xia, Yifan, et al.
Published: (2023)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
by: Zhou, Dongchao, et al.
Published: (2025)
by: Zhou, Dongchao, et al.
Published: (2025)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
From Coverage to Causes: Data-Centric Fuzzing for JavaScript Engines
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
by: Ganguly, Kishan Kumar, et al.
Published: (2025)
Securing P4 Programs by Information Flow Control
by: Alshnakat, Anoud, et al.
Published: (2025)
by: Alshnakat, Anoud, et al.
Published: (2025)
Breaking Obfuscation: Cluster-Aware Graph with LLM-Aided Recovery for Malicious JavaScript Detection
by: Liang, Zhihong, et al.
Published: (2025)
by: Liang, Zhihong, et al.
Published: (2025)
CASCADE: LLM-Powered JavaScript Deobfuscator at Google
by: Jiang, Shan, et al.
Published: (2025)
by: Jiang, Shan, et al.
Published: (2025)
Deserialization Gadget Chains are not a Pathological Problem in Android:an In-Depth Study of Java Gadget Chains in AOSP
by: Kreyssig, Bruno, et al.
Published: (2025)
by: Kreyssig, Bruno, et al.
Published: (2025)
Characterizing JavaScript Security Code Smells
by: Kambhampati, Vikas, et al.
Published: (2024)
by: Kambhampati, Vikas, et al.
Published: (2024)
The Hidden DNA of LLM-Generated JavaScript: Structural Patterns Enable High-Accuracy Authorship Attribution
by: Tihanyi, Norbert, et al.
Published: (2025)
by: Tihanyi, Norbert, et al.
Published: (2025)
Large Language Models Cannot Reliably Detect Vulnerabilities in JavaScript: The First Systematic Benchmark and Evaluation
by: Fei, Qingyuan, et al.
Published: (2025)
by: Fei, Qingyuan, et al.
Published: (2025)
Sleeping Giants -- Activating Dormant Java Deserialization Gadget Chains through Stealthy Code Changes
by: Kreyssig, Bruno, et al.
Published: (2025)
by: Kreyssig, Bruno, et al.
Published: (2025)
Classport: Designing Runtime Dependency Introspection for Java
by: Cofano, Serena, et al.
Published: (2025)
by: Cofano, Serena, et al.
Published: (2025)
Reasoning-Oriented Programming: Chaining Semantic Gadgets to Jailbreak Large Vision Language Models
by: Zou, Quanchen, et al.
Published: (2026)
by: Zou, Quanchen, et al.
Published: (2026)
CovRL: Fuzzing JavaScript Engines with Coverage-Guided Reinforcement Learning for LLM-based Mutation
by: Eom, Jueon, et al.
Published: (2024)
by: Eom, Jueon, et al.
Published: (2024)
Teapot: Efficiently Uncovering Spectre Gadgets in COTS Binaries
by: Lin, Fangzheng, et al.
Published: (2024)
by: Lin, Fangzheng, et al.
Published: (2024)
OverrideFuzz: Semantic-Aware Grammar Fuzzing for Script-Runtime Vulnerabilities
by: Qiu, Yiran
Published: (2026)
by: Qiu, Yiran
Published: (2026)
Directionality of the Voynich Script
by: Parisel, Christophe
Published: (2025)
by: Parisel, Christophe
Published: (2025)
Towards identifying Source credibility on Information Leakage in Digital Gadget Market
by: Kumaru, Neha, et al.
Published: (2024)
by: Kumaru, Neha, et al.
Published: (2024)
SoK: Runtime Integrity
by: Ammar, Mahmoud, et al.
Published: (2024)
by: Ammar, Mahmoud, et al.
Published: (2024)
Trace Gadgets: Minimizing Code Context for Machine Learning-Based Vulnerability Prediction
by: Mächtle, Felix, et al.
Published: (2025)
by: Mächtle, Felix, et al.
Published: (2025)
Similar Items
-
NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.js
by: Cornelissen, Eric, et al.
Published: (2025) -
Granite: Granular Runtime Enforcement for GitHub Actions Permissions
by: Moazen, Mojtaba, et al.
Published: (2025) -
Weaver: Fuzzing JavaScript Engines at the JavaScript-WebAssembly Boundary
by: Zhang, Lingming, et al.
Published: (2026) -
Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
by: Ali, Mir Masood, et al.
Published: (2024) -
Blocking Tracking JavaScript at the Function Granularity
by: Amjad, Abdul Haddi, et al.
Published: (2024)