{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:42:05Z","timestamp":1785512525714,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":132,"publisher":"ACM","funder":[{"name":"The Dutch Research Council (NWO)","award":["NWA.1215.18.008 Cyber Security by Integrated Design (C-SIDe)"],"award-info":[{"award-number":["NWA.1215.18.008 Cyber Security by Integrated Design (C-SIDe)"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3736220","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:33:18Z","timestamp":1755066798000},"page":"542-558","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Eradicating the Unseen: Detecting, Exploiting, and Remediating a Path Traversal Vulnerability across GitHub"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-8260-9508","authenticated-orcid":false,"given":"Jafar","family":"Akhoundali","sequence":"first","affiliation":[{"name":"Leiden University, Leiden, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-6101-4505","authenticated-orcid":false,"given":"Hamidreza","family":"Hamidi","sequence":"additional","affiliation":[{"name":"Technical and Vocational University, Mashhad, Iran"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0455-3430","authenticated-orcid":false,"given":"Kristian","family":"Rietveld","sequence":"additional","affiliation":[{"name":"Leiden University, Leiden, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3760-9165","authenticated-orcid":false,"given":"Olga","family":"Gadyatskaya","sequence":"additional","affiliation":[{"name":"Leiden University, Leiden, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_3_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3663533.3664036"},{"key":"e_1_3_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/WIECON-ECE60392.2023.10456393"},{"key":"e_1_3_3_3_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/NLBSE59153.2023.00008"},{"key":"e_1_3_3_3_5_2","doi-asserted-by":"crossref","unstructured":"Thanassis Avgerinos Sang\u00a0Kil Cha Alexandre Rebert Edward\u00a0J Schwartz Maverick Woo and David Brumley. 2014. Automatic exploit generation. Commun. ACM 57 2 (2014) 74\u201384.","DOI":"10.1145\/2560217.2560219"},{"key":"e_1_3_3_3_6_2","unstructured":"Jessy Ayala Yu-Jye Tung and Joshua Garcia. 2024. A mixed-methods study of open-source software maintainers on vulnerability management and platform security features. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2409.07669 (2024)."},{"key":"e_1_3_3_3_7_2","doi-asserted-by":"crossref","unstructured":"Michael Bailey David Dittrich Erin Kenneally and Doug Maughan. 2012. The Menlo report. IEEE Security & Privacy 10 2 (2012) 71\u201375.","DOI":"10.1109\/MSP.2012.52"},{"key":"e_1_3_3_3_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM51674.2020.00027"},{"key":"e_1_3_3_3_9_2","doi-asserted-by":"crossref","unstructured":"Ohad Barzilay and Cathy Urquhart. 2014. Understanding reuse of software examples: A case study of prejudice in a community of practice. Information and Software Technology 56 12 (2014) 1613\u20131628.","DOI":"10.1016\/j.infsof.2014.02.013"},{"key":"e_1_3_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3661167.3661262"},{"key":"e_1_3_3_3_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447852.3458718"},{"key":"e_1_3_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3475960.3475985"},{"key":"e_1_3_3_3_13_2","unstructured":"Blackduck. 2024. 2024 Open Source Security and Risk Analysis Report. https:\/\/www.blackduck.com\/resources\/analyst-reports\/open-source-security-risk-analysis.html"},{"key":"e_1_3_3_3_14_2","unstructured":"Knut Blind Mirko B\u00f6hm Paula Grzegorzewska Andrew Katz Sachiko Muto Sivan P\u00e4tsch and Torben Schubert. 2021. The impact of Open Source Software and Hardware on technological independence competitiveness and innovation in the EU economy. Final Study Report. European Commission Brussels doi 10 (2021) 430161."},{"key":"e_1_3_3_3_15_2","unstructured":"Islem Bouzenia and Michael Pradel. 2024. You name it I run it: An LLM agent to execute tests of arbitrary projects. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2412.10133 (2024)."},{"key":"e_1_3_3_3_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00012"},{"key":"e_1_3_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.17"},{"key":"e_1_3_3_3_18_2","doi-asserted-by":"crossref","unstructured":"Quang-Cuong Bui Ranindya Paramitha Duc-Ly Vu Fabio Massacci and Riccardo Scandariato. 2024. APR4Vul: An empirical study of automatic program repair techniques on real-world Java vulnerabilities. Empirical software engineering 29 1 (2024) 18.","DOI":"10.1007\/s10664-023-10415-7"},{"key":"e_1_3_3_3_19_2","doi-asserted-by":"crossref","unstructured":"Darion Cassel Nuno Sabino Ruben Martins and Limin Jia. 2024. NODEMEDIC-FINE: Automatic Detection and Exploit Synthesis for Node. js Vulnerabilities.","DOI":"10.14722\/ndss.2025.241636"},{"key":"e_1_3_3_3_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00068"},{"key":"e_1_3_3_3_21_2","volume-title":"WEIS","author":"Cavusoglu Hasan","year":"2005","unstructured":"Hasan Cavusoglu, Huseyin Cavusoglu, and Srinivasan Raghunathan. 2005. Emerging Issues in Responsible Vulnerability Disclosure.. In WEIS."},{"key":"e_1_3_3_3_22_2","first-page":"1","volume-title":"WEIS 2017","author":"\u00c7etin FO","year":"2017","unstructured":"FO \u00c7etin, Carlos Ganan, Maciej Korczynski, and Michel Van\u00a0Eeten. 2017. Make notifications great again: learning how to notify in the age of large-scale vulnerability scanning. In WEIS 2017. 1\u201323."},{"key":"e_1_3_3_3_23_2","doi-asserted-by":"crossref","unstructured":"Saikat Chakraborty Rahul Krishna Yangruibo Ding and Baishakhi Ray. 2021. Deep learning based vulnerability detection: Are we there yet? IEEE Transactions on Software Engineering 48 9 (2021) 3280\u20133296.","DOI":"10.1109\/TSE.2021.3087402"},{"key":"e_1_3_3_3_24_2","doi-asserted-by":"crossref","unstructured":"Xiangping Chen Furen Xu Yuan Huang Xiaocong Zhou and Zibin Zheng. 2024. An empirical study of code reuse between GitHub and stack overflow during software development. Journal of Systems and Software 210 (2024) 111964.","DOI":"10.1016\/j.jss.2024.111964"},{"key":"e_1_3_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3639478.3647633"},{"key":"e_1_3_3_3_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC.2011.26"},{"key":"e_1_3_3_3_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3643916.3644416"},{"key":"e_1_3_3_3_28_2","unstructured":"Leuson Da\u00a0Silva Jordan Samhi and Foutse Khomh. 2024. ChatGPT vs LLaMA: Impact Reliability and Challenges in Stack Overflow Discussions. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2402.08801 (2024)."},{"key":"e_1_3_3_3_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00074"},{"key":"e_1_3_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598130"},{"key":"e_1_3_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-FoSE59343.2023.00008"},{"key":"e_1_3_3_3_32_2","first-page":"829","volume-title":"33rd USENIX Security Symposium","author":"Fang Chongzhou","year":"2024","unstructured":"Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu, Ruoyu Zhang, Ruijie Fang, Ryan Tsang, Najmeh Nazari, Han Wang, Houman Homayoun, et\u00a0al. 2024. Large Language Models for Code Analysis: Do LLMs Really Do Their Job?. In 33rd USENIX Security Symposium. 829\u2013846."},{"key":"e_1_3_3_3_33_2","unstructured":"Richard Fang Rohan Bindu Akul Gupta and Daniel Kang. 2024. Llm agents can autonomously exploit one-day vulnerabilities. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2404.08144 (2024)."},{"key":"e_1_3_3_3_34_2","unstructured":"Richard Fang Rohan Bindu Akul Gupta Qiusi Zhan and Daniel Kang. 2024. Llm agents can autonomously hack websites. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2402.06664 (2024)."},{"key":"e_1_3_3_3_35_2","doi-asserted-by":"crossref","unstructured":"Zhiwei Fei Jidong Ge Chuanyi Li Tianqi Wang Yuning Li Haodong Zhang LiGuo Huang and Bin Luo. 2025. Patch Correctness Assessment: A Survey. ACM Transactions on Software Engineering and Methodology 34 2 (2025) 1\u201350.","DOI":"10.1145\/3702972"},{"key":"e_1_3_3_3_36_2","first-page":"1867","volume-title":"33rd USENIX Security Symposium","author":"Feng Siyue","year":"2024","unstructured":"Siyue Feng, Yueming Wu, Wenjie Xue, Sikui Pan, Deqing Zou, Yang Liu, and Hai Jin. 2024. FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability Detection. In 33rd USENIX Security Symposium. 1867\u20131884."},{"key":"e_1_3_3_3_37_2","unstructured":"FIRST.Org Inc.2015. Common Vulnerability Scoring System v3.0: Specification Document. https:\/\/www.first.org\/cvss\/v3.0\/specification-document. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.31"},{"key":"e_1_3_3_3_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"e_1_3_3_3_40_2","unstructured":"GH Archive Project. 2024. GH Archive. https:\/\/www.gharchive.org\/"},{"key":"e_1_3_3_3_41_2","unstructured":"GitHub. 2025. CodeQL: Semantic Code Analysis Engine. https:\/\/codeql.github.com\/. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_42_2","unstructured":"GitHub. 2025. GitHub Search: Public Repositories. https:\/\/github.com\/search?q=is%3Apublic&type=repositories. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_43_2","unstructured":"GitHub Community. 2022. Only 100 results? https:\/\/github.com\/orgs\/community\/discussions\/9868. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_44_2","doi-asserted-by":"crossref","unstructured":"Ken\u00a0Russel Go Sruthi Soundarapandian Aparupa Mitra Melina Vidoni and Nicol\u00e1s E\u00a0D\u00edaz Ferreyra. 2023. Simple stupid insecure practices and GitHub\u2019s code search: A looming threat? Journal of Systems and Software 202 (2023) 111698.","DOI":"10.1016\/j.jss.2023.111698"},{"key":"e_1_3_3_3_45_2","unstructured":"Google. 2024. From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code. https:\/\/googleprojectzero.blogspot.com\/2024\/10\/from-naptime-to-big-sleep.html"},{"key":"e_1_3_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2013.6624034"},{"key":"e_1_3_3_3_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW63631.2024.00014"},{"key":"e_1_3_3_3_48_2","doi-asserted-by":"crossref","unstructured":"Nikolay Harutyunyan. 2020. Managing your open source supply chain \u2013 why and how? Computer 53 6 (2020) 77\u201381.","DOI":"10.1109\/MC.2020.2983530"},{"key":"e_1_3_3_3_49_2","first-page":"177","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Hu Hong","year":"2015","unstructured":"Hong Hu, Zheng\u00a0Leong Chua, Sendroiu Adrian, Prateek Saxena, and Zhenkai Liang. 2015. Automatic Generation of Data-Oriented Exploits. In 24th USENIX Security Symposium (USENIX Security 15). 177\u2013192."},{"key":"e_1_3_3_3_50_2","unstructured":"Ruida Hu Chao Peng Xinchen Wang and Cuiyun Gao. 2025. An LLM-based Agent for Reliable Docker Environment Configuration. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2502.13681 (2025)."},{"key":"e_1_3_3_3_51_2","doi-asserted-by":"crossref","unstructured":"Junjie Huang and Quanyan Zhu. 2024. PenHeal: A Two-Stage LLM Framework for Automated Pentesting and Optimal Remediation. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2407.17788 (2024).","DOI":"10.2139\/ssrn.4941478"},{"key":"e_1_3_3_3_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3613892"},{"key":"e_1_3_3_3_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179352"},{"key":"e_1_3_3_3_54_2","first-page":"4041","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Kaur Harjot","year":"2022","unstructured":"Harjot Kaur, Sabrina Amft, Daniel Votipka, Yasemin Acar, and Sascha Fahl. 2022. Where to recruit for security development studies: Comparing six software developer samples. In 31st USENIX Security Symposium (USENIX Security 22). 4041\u20134058."},{"key":"e_1_3_3_3_55_2","doi-asserted-by":"crossref","unstructured":"Erin Kenneally and David Dittrich. 2012. The Menlo report: Ethical principles guiding information and communication technology research. Available at SSRN 2445102 (2012).","DOI":"10.2139\/ssrn.2445102"},{"key":"e_1_3_3_3_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/SMC53992.2023.10394237"},{"key":"e_1_3_3_3_57_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24018"},{"key":"e_1_3_3_3_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.62"},{"key":"e_1_3_3_3_59_2","unstructured":"Denis Kocetkov Raymond Li Loubna\u00a0Ben Allal Jia Li Chenghao Mou Carlos\u00a0Mu\u00f1oz Ferrandis Yacine Jernite Margaret Mitchell Sean Hughes Thomas Wolf et\u00a0al. 2022. The stack: 3 tb of permissively licensed source code. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2211.15533 (2022)."},{"key":"e_1_3_3_3_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664646.3664770"},{"key":"e_1_3_3_3_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179304"},{"key":"e_1_3_3_3_62_2","unstructured":"Jonathan Leitschuh and Patrick Way. 2022. Scaling the Security Researcher to Eliminate OSS Vulnerabilities Once and For All. Black Hat USA 2022. https:\/\/www.blackhat.com\/us-22\/briefings\/schedule\/#scaling-the-security-researcher-to-eliminate-oss-vulnerabilities-once-and-for-all-27131 Presentation at Black Hat USA 2022 Las Vegas NV August 2022."},{"key":"e_1_3_3_3_63_2","unstructured":"J. Leon. 2024. LLMs are Teaching Developers to Hardcode API Keys. https:\/\/trufflesecurity.com\/blog\/llms-are-teaching-developers-to-hardcode-api-keys"},{"key":"e_1_3_3_3_64_2","unstructured":"LGTM. 2025. LGTM Code Search. https:\/\/lgtm.com. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_65_2","doi-asserted-by":"crossref","unstructured":"H Li D He X Zhu and S Chan. 2022. P1OVD: Patch-Based 1-Day Out-of-Bounds Vulnerabilities Detection Tool for Downstream Binaries. Electronics (2022) 143.","DOI":"10.3390\/electronics11020260"},{"key":"e_1_3_3_3_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468542"},{"key":"e_1_3_3_3_67_2","unstructured":"Xuetao Li Yuxia Zhang Cailean Osborne Minghui Zhou Zhi Jin and Hui Liu. 2024. Systematic literature review of commercial participation in open source software. ACM Transactions on Software Engineering and Methodology (2024)."},{"key":"e_1_3_3_3_68_2","unstructured":"Jiawei Liu Chunqiu\u00a0Steven Xia Yuyao Wang and Lingming Zhang. 2024. Is your code generated by ChatGPT really correct? rigorous evaluation of large language models for code generation. Advances in Neural Information Processing Systems 36 (2024)."},{"key":"e_1_3_3_3_69_2","doi-asserted-by":"publisher","DOI":"10.5555\/3698900.3698946"},{"key":"e_1_3_3_3_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICNC59896.2024.10556123"},{"key":"e_1_3_3_3_71_2","doi-asserted-by":"crossref","unstructured":"Cristina\u00a0V Lopes Petr Maj Pedro Martins Vaibhav Saini Di Yang Jakub Zitny Hitesh Sajnani and Jan Vitek. 2017. D\u00e9j\u00e0Vu: a map of code duplicates on GitHub. Proceedings of the ACM on Programming Languages 1 OOPSLA (2017) 1\u201328.","DOI":"10.1145\/3133908"},{"key":"e_1_3_3_3_72_2","doi-asserted-by":"crossref","unstructured":"Guilong Lu Xiaolin Ju Xiang Chen Wenlong Pei and Zhilong Cai. 2024. GRACE: Empowering LLM-based software vulnerability detection with graph structure and in-context learning. Journal of Systems and Software 212 (2024) 112031.","DOI":"10.1016\/j.jss.2024.112031"},{"key":"e_1_3_3_3_73_2","doi-asserted-by":"crossref","unstructured":"Kevin Macnish and Jeroen Van\u00a0der Ham. 2020. Ethics in cybersecurity research and practice. Technology in society 63 (2020) 101382.","DOI":"10.1016\/j.techsoc.2020.101382"},{"key":"e_1_3_3_3_74_2","doi-asserted-by":"crossref","unstructured":"Sanoop Mallissery and Yu-Sung Wu. 2023. Demystify the fuzzing methods: A comprehensive survey. Comput. Surveys 56 3 (2023) 1\u201338.","DOI":"10.1145\/3623375"},{"key":"e_1_3_3_3_75_2","doi-asserted-by":"crossref","unstructured":"Tina Marjanov Ivan Pashchenko and Fabio Massacci. 2022. Machine learning for source code vulnerability detection: What works and what isn\u2019t there yet. IEEE Security & Privacy 20 5 (2022) 60\u201376.","DOI":"10.1109\/MSEC.2022.3176058"},{"key":"e_1_3_3_3_76_2","unstructured":"Dan McInerney and Marcello Salvati. 2024. Vulnhuntr: Autonomous AI Finds First 0-Day Vulnerabilities in Wild. https:\/\/protectai.com\/threat-research\/vulnhuntr-first-0-day-vulnerabilities"},{"key":"e_1_3_3_3_77_2","unstructured":"MITRE. 2024. 2024 CWE Top 10 KEV Weaknesses. https:\/\/cwe.mitre.org\/top25\/archive\/2024\/2024_kev_list.html. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_78_2","unstructured":"MITRE. 2024. 2024 CWE Top 25 Most Dangerous Software Weaknesses. https:\/\/cwe.mitre.org\/top25\/archive\/2024\/2024_cwe_top25.html. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_79_2","unstructured":"MITRE. 2024. CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u2019Path Traversal\u2019). https:\/\/cwe.mitre.org\/data\/definitions\/22.html. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664646.3664777"},{"key":"e_1_3_3_3_81_2","volume-title":"SOUPS Workshop on Security Information Workers (WSIW). USENIX Association","author":"Mokhberi Azadeh","year":"2021","unstructured":"Azadeh Mokhberi, Tiffany Quon, and Konstantin Beznosov. 2021. What makes security-related code examples different. In SOUPS Workshop on Security Information Workers (WSIW). USENIX Association."},{"key":"e_1_3_3_3_82_2","doi-asserted-by":"crossref","unstructured":"Giovane\u00a0CM Moura and John Heidemann. 2023. Vulnerability Disclosure Considered Stressful. ACM SIGCOMM Computer Communication Review 53 2 (2023) 2\u201310.","DOI":"10.1145\/3610381.3610383"},{"key":"e_1_3_3_3_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3661134"},{"key":"e_1_3_3_3_84_2","unstructured":"Yu Nong Haoran Yang Long Cheng Hongxin Hu and Haipeng Cai. 2024. Automated Software Vulnerability Patching using Large Language Models. arxiv:https:\/\/arXiv.org\/abs\/2408.13597\u00a0[cs.CR] https:\/\/arxiv.org\/abs\/2408.13597"},{"key":"e_1_3_3_3_85_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"e_1_3_3_3_86_2","unstructured":"Online. 2010. https:\/\/gist.github.com\/ryanflorence\/701407\/revisions"},{"key":"e_1_3_3_3_87_2","unstructured":"Online. 2011. . https:\/\/stackoverflow.com\/questions\/7268033\/basic-static-file-server-in-nodejs"},{"key":"e_1_3_3_3_88_2","unstructured":"Online. 2015. . https:\/\/stackoverflow.com\/a\/29046869"},{"key":"e_1_3_3_3_89_2","unstructured":"Online. 2017. https:\/\/github.com\/iproduct\/course-node-express-react"},{"key":"e_1_3_3_3_90_2","unstructured":"Online. 2017. https:\/\/github.com\/ARVILab\/CourseAI"},{"key":"e_1_3_3_3_91_2","unstructured":"Online. 2019. https:\/\/github.com\/bradtraversy\/node_crash_course"},{"key":"e_1_3_3_3_92_2","unstructured":"Online. 2024. https:\/\/github.com\/mdn\/content\/commit\/eb79c92ae89e15a7dbc996150abd7f9930f3e5af"},{"key":"e_1_3_3_3_93_2","unstructured":"Online. 2024. https:\/\/github.com\/MichaelGustavsson\/nodejs-course"},{"key":"e_1_3_3_3_94_2","unstructured":"Online. 2025. https:\/\/data.stackexchange.com\/stackoverflow\/query\/1854595\/most-viewed-questions-for-specific-tag"},{"key":"e_1_3_3_3_95_2","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2803191"},{"key":"e_1_3_3_3_96_2","first-page":"197","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Park Sunnyeo","year":"2022","unstructured":"Sunnyeo Park, Daejun Kim, Suman Jana, and Sooel Son. 2022. FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities. In 31st USENIX Security Symposium (USENIX Security 22). 197\u2013214."},{"key":"e_1_3_3_3_97_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833571"},{"key":"e_1_3_3_3_98_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179420"},{"key":"e_1_3_3_3_99_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2019.00066"},{"key":"e_1_3_3_3_100_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE52982.2021.00031"},{"key":"e_1_3_3_3_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2019.00087"},{"key":"e_1_3_3_3_102_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510216"},{"key":"e_1_3_3_3_103_2","doi-asserted-by":"publisher","DOI":"10.1109\/SANER50967.2021.00064"},{"key":"e_1_3_3_3_104_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"e_1_3_3_3_105_2","doi-asserted-by":"publisher","DOI":"10.1145\/3661167.3661207"},{"key":"e_1_3_3_3_106_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884877"},{"key":"e_1_3_3_3_107_2","unstructured":"Semgrep Inc.2025. Semgrep: Static Analysis for Modern Development. https:\/\/semgrep.dev\/. Accessed: 2025-05-20."},{"key":"e_1_3_3_3_108_2","unstructured":"Aadit\u00a0M Shah. [n. d.]. Why do people fork repositories on GitHub? Software Engineering Stack Exchange. arXiv:https:\/\/softwareengineering.stackexchange.com\/q\/200663https:\/\/softwareengineering.stackexchange.com\/q\/200663 URL:https:\/\/softwareengineering.stackexchange.com\/q\/200663 (version: 2013-06-06)."},{"key":"e_1_3_3_3_109_2","first-page":"5521","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Shcherbakov Mikhail","year":"2023","unstructured":"Mikhail Shcherbakov, Musard Balliu, and Cristian-Alexandru Staicu. 2023. Silent spring: Prototype pollution leads to remote code execution in Node. js. In 32nd USENIX Security Symposium (USENIX Security 23). 5521\u20135538."},{"key":"e_1_3_3_3_110_2","doi-asserted-by":"crossref","unstructured":"Zhidong Shen and Si Chen. 2020. A survey of automatic software vulnerability detection program repair and defect prediction techniques. Security and Communication Networks 2020 1 (2020) 8858010.","DOI":"10.1155\/2020\/8858010"},{"key":"e_1_3_3_3_111_2","doi-asserted-by":"crossref","unstructured":"Ze Sheng Fenghua Wu Xiangwu Zuo Chao Li Yuxin Qiao and Lei Hang. 2024. Lprotector: An llm-driven vulnerability detection system. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2411.06493 (2024).","DOI":"10.1109\/ICDSCA63855.2024.10859408"},{"key":"e_1_3_3_3_112_2","doi-asserted-by":"publisher","DOI":"10.1109\/CHASE.2013.6614738"},{"key":"e_1_3_3_3_113_2","doi-asserted-by":"crossref","unstructured":"Morteza Verdi Ashkan Sami Jafar Akhondali Foutse Khomh Gias Uddin and Alireza\u00a0Karami Motlagh. 2020. An empirical study of C++ vulnerabilities in crowd-sourced code examples. IEEE Transactions on Software Engineering 48 5 (2020) 1497\u20131514.","DOI":"10.1109\/TSE.2020.3023664"},{"key":"e_1_3_3_3_114_2","unstructured":"Jin Wang Zishan Huang Hengli Liu Nianyi Yang and Yinhao Xiao. 2023. Defecthunter: A novel llm-driven boosted-conformer-based code vulnerability detection mechanism. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2309.15324 (2023)."},{"key":"e_1_3_3_3_115_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416590"},{"key":"e_1_3_3_3_116_2","doi-asserted-by":"crossref","unstructured":"Emily Winter David Bowes Steve Counsell Tracy Hall S\u00e6mundur Haraldsson Vesna Nowack and John Woodward. 2022. How do developers really feel about bug fixing? Directions for automatic program repair. IEEE Transactions on Software Engineering (2022).","DOI":"10.1109\/TSE.2022.3194188"},{"key":"e_1_3_3_3_117_2","first-page":"6541","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Woo Seunghoon","year":"2023","unstructured":"Seunghoon Woo, Eunjin Choi, Heejo Lee, and Hakjoo Oh. 2023. V1SCAN: Discovering 1-day Vulnerabilities in Reused C\/C++ Open-source Software Components Using Code Classification Techniques. In 32nd USENIX Security Symposium (USENIX Security 23). 6541\u20136556."},{"key":"e_1_3_3_3_118_2","first-page":"3037","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Woo Seunghoon","year":"2022","unstructured":"Seunghoon Woo, Hyunji Hong, Eunjin Choi, and Heejo Lee. 2022. MOVERY: A Precise Approach for Modified Vulnerable Code Clone Discovery from Modified Open-Source Software Components. In 31st USENIX Security Symposium (USENIX Security 22). 3037\u20133053."},{"key":"e_1_3_3_3_119_2","first-page":"3041","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Woo Seunghoon","year":"2021","unstructured":"Seunghoon Woo, Dongwook Lee, Sunghan Park, Heejo Lee, and Sven Dietrich. 2021. V0Finder: Discovering the Correct Origin of Publicly Reported Software Vulnerabilities. In 30th USENIX Security Symposium (USENIX Security 21). 3041\u20133058."},{"key":"e_1_3_3_3_120_2","unstructured":"Benlong Wu Guoqiang Chen Kejiang Chen Xiuwei Shang Jiapeng Han Yanru He Weiming Zhang and Nenghai Yu. 2024. AutoPT: How Far Are We from the End2End Automated Web Penetration Testing? arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2411.01236 (2024)."},{"key":"e_1_3_3_3_121_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598135"},{"key":"e_1_3_3_3_122_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00129"},{"key":"e_1_3_3_3_123_2","unstructured":"Jiacen Xu Jack\u00a0W Stokes Geoff McDonald Xuesong Bai David Marshall Siyue Wang Adith Swaminathan and Zhou Li. 2024. Autoattacker: A large language model guided system to implement automatic cyber-attacks. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2403.01038 (2024)."},{"key":"e_1_3_3_3_124_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS54544.2021.00060"},{"key":"e_1_3_3_3_125_2","doi-asserted-by":"crossref","unstructured":"Zhou Yang Zhipeng Zhao Chenyu Wang Jieke Shi Dongsun Kim Donggyun Han and David Lo. 2024. Gotcha! This model uses my code! evaluating membership leakage risks in code models. IEEE Transactions on Software Engineering (2024).","DOI":"10.1109\/TSE.2024.3482719"},{"key":"e_1_3_3_3_126_2","unstructured":"Burak Yeti\u015ftiren I\u015f\u0131k \u00d6zsoy Miray Ayerdem and Eray T\u00fcz\u00fcn. 2023. Evaluating the code quality of ai-assisted code generation tools: An empirical study on github copilot amazon codewhisperer and chatgpt. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2304.10778 (2023)."},{"key":"e_1_3_3_3_127_2","doi-asserted-by":"crossref","unstructured":"Haibo Zhang and Kouichi Sakurai. 2021. A survey of software clone detection from security perspective. IEEE Access 9 (2021) 48157\u201348173.","DOI":"10.1109\/ACCESS.2021.3065872"},{"key":"e_1_3_3_3_128_2","doi-asserted-by":"crossref","unstructured":"Jie Zhang Haoyu Bu Hui Wen Yongji Liu Haiqiang Fei Rongrong Xi Lun Li Yun Yang Hongsong Zhu and Dan Meng. 2025. When llms meet cybersecurity: A systematic literature review. Cybersecurity 8 1 (2025) 1\u201341.","DOI":"10.1186\/s42400-025-00361-w"},{"key":"e_1_3_3_3_129_2","unstructured":"Xin Zhou Sicong Cao Xiaobing Sun and David Lo. 2024. Large Language Model for Vulnerability Detection and Repair: Literature Review and Roadmap. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2404.02525 (2024)."},{"key":"e_1_3_3_3_130_2","doi-asserted-by":"crossref","unstructured":"Xiaogang Zhu Sheng Wen Seyit Camtepe and Yang Xiang. 2022. Fuzzing: a survey for roadmap. ACM Computing Surveys (CSUR) 54 11s (2022) 1\u201336.","DOI":"10.1145\/3512345"},{"key":"e_1_3_3_3_131_2","unstructured":"Yuxuan Zhu Antony Kellermann Dylan Bowman Philip Li Akul Gupta Adarsh Danda Richard Fang Conner Jensen Eric Ihli Jason Benn et\u00a0al. 2025. CVE-Bench: A Benchmark for AI Agents\u2019 Ability to Exploit Real-World Web Application Vulnerabilities. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2503.17332 (2025)."},{"key":"e_1_3_3_3_132_2","unstructured":"Yuxuan Zhu Antony Kellermann Akul Gupta Philip Li Richard Fang Rohan Bindu and Daniel Kang. 2024. Teams of llm agents can exploit zero-day vulnerabilities. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2406.01637 (2024)."},{"key":"e_1_3_3_3_133_2","first-page":"995","volume-title":"28th USENIX Security symposium (USENIX security 19)","author":"Zimmermann Markus","year":"2019","unstructured":"Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019. Small world with high risks: A study of security threats in the npm ecosystem. In 28th USENIX Security symposium (USENIX security 19). 995\u20131010."}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3736220","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:26:36Z","timestamp":1755069996000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3736220"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":132,"alternative-id":["10.1145\/3708821.3736220","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3736220","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}