From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Ullah, Saad, Balasubramanian, Praneeth, Guo, Wenbo, Burnett, Amanda, Pearce, Hammond, Kruegel, Christopher, Vigna, Giovanni, Stringhini, Gianluca
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915793500897280
author Ullah, Saad
Balasubramanian, Praneeth
Guo, Wenbo
Burnett, Amanda
Pearce, Hammond
Kruegel, Christopher
Vigna, Giovanni
Stringhini, Gianluca
author_facet Ullah, Saad
Balasubramanian, Praneeth
Guo, Wenbo
Burnett, Amanda
Pearce, Hammond
Kruegel, Christopher
Vigna, Giovanni
Stringhini, Gianluca
contents High-quality datasets of real-world vulnerabilities and their corresponding verifiable exploits are crucial resources in software security research. Yet such resources remain scarce, as their creation demands intensive manual effort and deep security expertise. In this paper, we present CVE-GENIE, an automated, large language model (LLM)-based multi-agent framework designed to reproduce real-world vulnerabilities, provided in Common Vulnerabilities and Exposures (CVE) format, to enable creation of high-quality vulnerability datasets. Given a CVE entry as input, CVE-GENIE gathers the relevant resources of the CVE, automatically reconstructs the vulnerable environment, and (re)produces a verifiable exploit. Our systematic evaluation highlights the efficiency and robustness of CVE-GENIE's design and successfully reproduces approximately 51% (428 of 841) CVEs published in 2024-2025, complete with their verifiable exploits, at an average cost of $2.77 per CVE. Our pipeline offers a robust method to generate reproducible CVE benchmarks, valuable for diverse applications such as fuzzer evaluation, vulnerability patching, and assessing AI's security capabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2509_01835
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs
Ullah, Saad
Balasubramanian, Praneeth
Guo, Wenbo
Burnett, Amanda
Pearce, Hammond
Kruegel, Christopher
Vigna, Giovanni
Stringhini, Gianluca
Cryptography and Security
High-quality datasets of real-world vulnerabilities and their corresponding verifiable exploits are crucial resources in software security research. Yet such resources remain scarce, as their creation demands intensive manual effort and deep security expertise. In this paper, we present CVE-GENIE, an automated, large language model (LLM)-based multi-agent framework designed to reproduce real-world vulnerabilities, provided in Common Vulnerabilities and Exposures (CVE) format, to enable creation of high-quality vulnerability datasets. Given a CVE entry as input, CVE-GENIE gathers the relevant resources of the CVE, automatically reconstructs the vulnerable environment, and (re)produces a verifiable exploit. Our systematic evaluation highlights the efficiency and robustness of CVE-GENIE's design and successfully reproduces approximately 51% (428 of 841) CVEs published in 2024-2025, complete with their verifiable exploits, at an average cost of $2.77 per CVE. Our pipeline offers a robust method to generate reproducible CVE benchmarks, valuable for diverse applications such as fuzzer evaluation, vulnerability patching, and assessing AI's security capabilities.
title From CVE Entries to Verifiable Exploits: An Automated Multi-Agent Framework for Reproducing CVEs
topic Cryptography and Security
url https://arxiv.org/abs/2509.01835