An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
Fuente:
arXiv
Saved in:
| Main Authors: | Liu, Shuhan, Hu, Xing, Xia, Xin, Lo, David, Yang, Xiaohu |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026)
by: Chen, Zirui, et al.
Published: (2026)
VulEval: Towards Repository-Level Evaluation of Software Vulnerability Detection
by: Wen, Xin-Cheng, et al.
Published: (2024)
by: Wen, Xin-Cheng, et al.
Published: (2024)
PPT4J: Patch Presence Test for Java Binaries
by: Pan, Zhiyuan, et al.
Published: (2023)
by: Pan, Zhiyuan, et al.
Published: (2023)
An Empirical Study of Vulnerabilities in Python Packages and Their Detection
by: Quan, Haowei, et al.
Published: (2025)
by: Quan, Haowei, et al.
Published: (2025)
ReposVul: A Repository-Level High-Quality Vulnerability Dataset
by: Wang, Xinchen, et al.
Published: (2024)
by: Wang, Xinchen, et al.
Published: (2024)
Exploiting LLM Agent Supply Chains via Payload-less Skills
by: Liu, Xinyu, et al.
Published: (2026)
by: Liu, Xinyu, et al.
Published: (2026)
An Empirical Study on the Security Vulnerabilities of GPTs
by: Wu, Tong, et al.
Published: (2025)
by: Wu, Tong, et al.
Published: (2025)
Similar but Patched Code Considered Harmful -- The Impact of Similar but Patched Code on Recurring Vulnerability Detection and How to Remove Them
by: Tan, Zixuan, et al.
Published: (2024)
by: Tan, Zixuan, et al.
Published: (2024)
Triggering and Detecting Exploitable Library Vulnerability from the Client by Directed Greybox Fuzzing
by: Zhao, Yukai, et al.
Published: (2026)
by: Zhao, Yukai, et al.
Published: (2026)
An Empirical Study of Vulnerability Handling Times in CPython
by: Ruohonen, Jukka
Published: (2024)
by: Ruohonen, Jukka
Published: (2024)
Characterizing Trust Boundary Vulnerabilities in TEE Containers: An Empirical Study
by: Liu, Weijie, et al.
Published: (2025)
by: Liu, Weijie, et al.
Published: (2025)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
An Empirical Study of Vulnerability Detection using Federated Learning
by: Zhou, Peiheng, et al.
Published: (2024)
by: Zhou, Peiheng, et al.
Published: (2024)
MegaVul: A C/C++ Vulnerability Dataset with Comprehensive Code Representation
by: Ni, Chao, et al.
Published: (2024)
by: Ni, Chao, et al.
Published: (2024)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
by: Cheng, Yiran, et al.
Published: (2024)
by: Cheng, Yiran, et al.
Published: (2024)
Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring Systems
by: Koscinski, Viktoria, et al.
Published: (2025)
by: Koscinski, Viktoria, et al.
Published: (2025)
Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities
by: Ma, Yujie, et al.
Published: (2026)
by: Ma, Yujie, et al.
Published: (2026)
Semantic Consensus Decoding: Backdoor Defense for Verilog Code Generation
by: Yang, Guang, et al.
Published: (2026)
by: Yang, Guang, et al.
Published: (2026)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages
by: Simsek, Deniz, et al.
Published: (2025)
by: Simsek, Deniz, et al.
Published: (2025)
Profile of Vulnerability Remediations in Dependencies Using Graph Analysis
by: Vera, Fernando, et al.
Published: (2024)
by: Vera, Fernando, et al.
Published: (2024)
Execution-State-Aware LLM Reasoning for Automated Proof-of-Vulnerability Generation
by: Li, Haoyu, et al.
Published: (2026)
by: Li, Haoyu, et al.
Published: (2026)
Bridging Expert Reasoning and LLM Detection: A Knowledge-Driven Framework for Malicious Packages
by: Guo, Wenbo, et al.
Published: (2026)
by: Guo, Wenbo, et al.
Published: (2026)
Coca: Improving and Explaining Graph Neural Network-Based Vulnerability Detection Systems
by: Cao, Sicong, et al.
Published: (2024)
by: Cao, Sicong, et al.
Published: (2024)
PatchSeeker: Mapping NVD Records to their Vulnerability-fixing Commits with LLM Generated Commits and Embeddings
by: Nguyen, Huu Hung, et al.
Published: (2025)
by: Nguyen, Huu Hung, et al.
Published: (2025)
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
ContractTinker: LLM-Empowered Vulnerability Repair for Real-World Smart Contracts
by: Wang, Che, et al.
Published: (2024)
by: Wang, Che, et al.
Published: (2024)
Semantics-Aligned, Curriculum-Driven, and Reasoning-Enhanced Vulnerability Repair Framework
by: Yang, Chengran, et al.
Published: (2025)
by: Yang, Chengran, et al.
Published: (2025)
Are Latent Vulnerabilities Hidden Gems for Software Vulnerability Prediction? An Empirical Study
by: Le, Triet H. M., et al.
Published: (2024)
by: Le, Triet H. M., et al.
Published: (2024)
SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
by: Lingxiang, Wang, et al.
Published: (2025)
by: Lingxiang, Wang, et al.
Published: (2025)
Evolution of Log-Based Detection Rules in Public Repositories
by: Long, Minjun, et al.
Published: (2026)
by: Long, Minjun, et al.
Published: (2026)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics
by: Li, Yikun, et al.
Published: (2024)
by: Li, Yikun, et al.
Published: (2024)
Smart Contract Fuzzing Towards Profitable Vulnerabilities
by: Kong, Ziqiao, et al.
Published: (2025)
by: Kong, Ziqiao, et al.
Published: (2025)
Beyond Function-Level Analysis: Context-Aware Reasoning for Inter-Procedural Vulnerability Detection
by: Li, Yikun, et al.
Published: (2026)
by: Li, Yikun, et al.
Published: (2026)
An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code
by: Elsayed, Mohamed, et al.
Published: (2026)
by: Elsayed, Mohamed, et al.
Published: (2026)
CHASE: LLM Agents for Dissecting Malicious PyPI Packages
by: Toda, Takaaki, et al.
Published: (2026)
by: Toda, Takaaki, et al.
Published: (2026)
Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the Web
by: Swierzy, Ben, et al.
Published: (2025)
by: Swierzy, Ben, et al.
Published: (2025)
What's in a Package? Getting Visibility Into Dependencies Using Security-Sensitive API Calls
by: Rahman, Imranur, et al.
Published: (2024)
by: Rahman, Imranur, et al.
Published: (2024)
Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects
by: Schott, Stefan, et al.
Published: (2026)
by: Schott, Stefan, et al.
Published: (2026)
Similar Items
-
A Large-scale Empirical Study on the Generalizability of Disclosed Java Library Vulnerability Exploits
by: Chen, Zirui, et al.
Published: (2026) -
VulEval: Towards Repository-Level Evaluation of Software Vulnerability Detection
by: Wen, Xin-Cheng, et al.
Published: (2024) -
PPT4J: Patch Presence Test for Java Binaries
by: Pan, Zhiyuan, et al.
Published: (2023) -
An Empirical Study of Vulnerabilities in Python Packages and Their Detection
by: Quan, Haowei, et al.
Published: (2025) -
ReposVul: A Repository-Level High-Quality Vulnerability Dataset
by: Wang, Xinchen, et al.
Published: (2024)