{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T21:19:41Z","timestamp":1783804781382,"version":"3.55.0"},"reference-count":82,"publisher":"Association for Computing Machinery (ACM)","issue":"OOPSLA1","license":[{"start":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T00:00:00Z","timestamp":1744156800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Shanghai Sailing Program","award":["22YF1428600"],"award-info":[{"award-number":["22YF1428600"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202306"],"award-info":[{"award-number":["62202306"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Program. Lang."],"published-print":{"date-parts":[[2025,4,9]]},"abstract":"<jats:p>Server-side request forgery (SSRF) vulnerabilities are inevitable in PHP web applications. Existing static tools in detecting vulnerabilities in PHP web applications neither contain SSRF-related features to enhance detection accuracy nor consider PHP\u2019s dynamic type features. In this paper, we present Artemis, a static taint analysis tool for detecting SSRF vulnerabilities in PHP web applications. First, Artemis extracts both PHP built-in and third-party functions as candidate source and sink functions. Second, Artemis constructs both explicit and implicit call graphs to infer functions\u2019 relationships. Third, Artemis performs taint analysis based on a set of rules that prevent over-tainting and pauses when SSRF exploitation is impossible. Fourth, Artemis analyzes the compatibility of path conditions to prune false positives. We have implemented a prototype of Artemis and evaluated it on 250 PHP web applications. Artemis reports 207 true vulnerable paths (106 true SSRFs) with 15 false positives. Of the 106 detected SSRFs, 35 are newly found and reported to developers, with 24 confirmed and assigned CVE IDs.<\/jats:p>","DOI":"10.1145\/3720488","type":"journal-article","created":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T13:48:26Z","timestamp":1744206506000},"page":"1349-1377","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-procedural Path-Sensitive Taint Analysis"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4828-5338","authenticated-orcid":false,"given":"Yuchen","family":"Ji","sequence":"first","affiliation":[{"name":"ShanghaiTech University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0257-2304","authenticated-orcid":false,"given":"Ting","family":"Dai","sequence":"additional","affiliation":[{"name":"IBM Research, Yorktown Heights, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4543-262X","authenticated-orcid":false,"given":"Zhichao","family":"Zhou","sequence":"additional","affiliation":[{"name":"ShanghaiTech University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5677-4564","authenticated-orcid":false,"given":"Yutian","family":"Tang","sequence":"additional","affiliation":[{"name":"University of Glasgow, Glasgow, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9448-5022","authenticated-orcid":false,"given":"Jingzhu","family":"He","sequence":"additional","affiliation":[{"name":"ShanghaiTech University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,9]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2019. What We Can Learn from the Capital One Hack. https:\/\/krebsonsecurity.com\/2019\/08\/what-we-can-learn-from-the-capital-one-hack"},{"key":"e_1_2_1_2_1","unstructured":"2022. CakePHP. https:\/\/cakephp.org\/"},{"key":"e_1_2_1_3_1","unstructured":"2022. Curl Class. https:\/\/www.phpcurlclass.com\/"},{"key":"e_1_2_1_4_1","unstructured":"2022. Guzzle PHP HTTP client. https:\/\/github.com\/guzzle\/guzzle"},{"key":"e_1_2_1_5_1","unstructured":"2022. Laravel Request. https:\/\/laravel.com\/api\/11.x\/Illuminate\/Http\/Request.html"},{"key":"e_1_2_1_6_1","unstructured":"2022. phan. https:\/\/github.com\/phan\/phan"},{"key":"e_1_2_1_7_1","unstructured":"2022. phan-plugin. https:\/\/github.com\/wikimedia\/mediawiki-tools-phan-SecurityCheckPlugin"},{"key":"e_1_2_1_8_1","unstructured":"2022. Yii Request. https:\/\/www.yiiframework.com\/doc\/api\/2.0\/yii-web-request"},{"key":"e_1_2_1_9_1","unstructured":"2023. Awesome-Selfhosted. https:\/\/github.com\/awesome-selfhosted\/awesome-selfhosted"},{"key":"e_1_2_1_10_1","unstructured":"2023. CVE database. https:\/\/cve.mitre.org\/index.html"},{"key":"e_1_2_1_11_1","unstructured":"2023. CWE-918: Server-Side Request Forgery (SSRF). https:\/\/cwe.mitre.org\/data\/definitions\/918.html"},{"key":"e_1_2_1_12_1","unstructured":"2023. function.extract. https:\/\/www.php.net\/manual\/en\/function.extract.php"},{"key":"e_1_2_1_13_1","unstructured":"2023. Joern. https:\/\/github.com\/joernio\/joern"},{"key":"e_1_2_1_14_1","unstructured":"2023. Magic Methods. https:\/\/www.php.net\/manual\/en\/language.oop5.overloading.php"},{"key":"e_1_2_1_15_1","unstructured":"2023. php-ast. https:\/\/github.com\/nikic\/php-ast"},{"key":"e_1_2_1_16_1","unstructured":"2023. Popular Plugins. https:\/\/wordpress.org\/plugins\/browse\/popular"},{"key":"e_1_2_1_17_1","unstructured":"2023. PSR-5: PHPDoc. https:\/\/github.com\/php-fig\/fig-standards\/blob\/master\/proposed\/phpdoc.md"},{"key":"e_1_2_1_18_1","unstructured":"2023. Superglobals. https:\/\/www.php.net\/manual\/en\/language.variables.superglobals.php"},{"key":"e_1_2_1_19_1","unstructured":"2023. Usage statistics of PHP for websites. https:\/\/w3techs.com\/technologies\/details\/pl-php"},{"key":"e_1_2_1_20_1","unstructured":"2024. Arrow Functions. https:\/\/www.php.net\/manual\/en\/functions.arrow.php"},{"key":"e_1_2_1_21_1","unstructured":"2024. Claude 3.5 Sonnet. https:\/\/www.anthropic.com\/news\/claude-3-5-sonnet"},{"key":"e_1_2_1_22_1","unstructured":"2024. GPT-4o. https:\/\/platform.openai.com\/docs\/models\/gpt-4o"},{"key":"e_1_2_1_23_1","unstructured":"2024. Object Inheritance. https:\/\/www.php.net\/manual\/en\/language.oop5.inheritance.php"},{"key":"e_1_2_1_24_1","unstructured":"2024. OWASP Top 10 - 2021. https:\/\/owasp.org\/Top10\/"},{"key":"e_1_2_1_25_1","unstructured":"2024. Phan Type Inference Wiki. https:\/\/github.com\/phan\/phan\/wiki\/Phan-Config-Settings#allow_overriding_vague_return_types"},{"key":"e_1_2_1_26_1","unstructured":"2024. Prompt engineering. https:\/\/platform.openai.com\/docs\/guides\/prompt-engineering"},{"key":"e_1_2_1_27_1","unstructured":"2024. psalm. https:\/\/github.com\/vimeo\/psalm\/"},{"key":"e_1_2_1_28_1","unstructured":"2024. Reflection. https:\/\/www.php.net\/manual\/en\/intro.reflection.php"},{"key":"e_1_2_1_29_1","unstructured":"2024. Type System. https:\/\/www.php.net\/manual\/en\/language.types.intro.php"},{"key":"e_1_2_1_30_1","unstructured":"2024. Variable Functions. https:\/\/www.php.net\/manual\/en\/functions.variable-functions.php \/"},{"key":"e_1_2_1_31_1","unstructured":"2024. Variable-length argument lists. https:\/\/www.php.net\/manual\/en\/functions.arguments.php#functions.variable-arg-list"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277232"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","unstructured":"Michael Backes Konrad Rieck Malte Skoruppa Ben Stock and Fabian Yamaguchi. 2017. Efficient and flexible discovery of php application vulnerabilities. In 2017 IEEE european symposium on security and privacy (EuroS&P). 334\u2013349. https:\/\/doi.org\/10.1109\/EuroSP.2017.14 10.1109\/EuroSP.2017.14","DOI":"10.1109\/EuroSP.2017.14"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447852.3458718"},{"key":"e_1_2_1_35_1","volume-title":"McCahill","author":"Berners-Lee Tim","year":"1994","unstructured":"Tim Berners-Lee, Larry M Masinter, and Mark P. McCahill. 1994. Uniform Resource Locators (URL). RFC 1738. https:\/\/www.rfc-editor.org\/info\/rfc1738"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46669-8_21"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00150"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/3361338.3361390"},{"key":"e_1_2_1_39_1","first-page":"23","article-title":"Simulation of Built-in PHP Features for Precise Static Code Analysis","volume":"14","author":"Dahse Johannes","year":"2014","unstructured":"Johannes Dahse and Thorsten Holz. 2014. Simulation of Built-in PHP Features for Precise Static Code Analysis.. In NDSS. 14, 23\u201326.","journal-title":"NDSS."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671288"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616582"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484745"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44202-9_23"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESTEL.2012.6400112"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833753"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.5555\/3698900.3699167"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471859"},{"key":"e_1_2_1_48_1","volume-title":"Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-Procedural Path-Sensitive Taint Analysis. arxiv:2502.21026.","author":"Ji Yuchen","year":"2025","unstructured":"Yuchen Ji, Ting Dai, Zhichao Zhou, Yutian Tang, and Jingzhu He. 2025. Artemis: Toward Accurate Detection of Server-Side Request Forgeries through LLM-Assisted Inter-Procedural Path-Sensitive Taint Analysis. arxiv:2502.21026."},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.36"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179352"},{"key":"e_1_2_1_51_1","doi-asserted-by":"crossref","unstructured":"Zifeng Kang Song Li and Yinzhi Cao. 2022. Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites.. In NDSS.","DOI":"10.14722\/ndss.2022.24308"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485888"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00098"},{"key":"e_1_2_1_54_1","volume-title":"JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative Traversals. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Khodayari Soheil","year":"2021","unstructured":"Soheil Khodayari and Giancarlo Pellegrino. 2021. JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative Traversals. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2525\u20132542. isbn:978-1-939133-24-3"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179403"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380355"},{"key":"e_1_2_1_57_1","volume-title":"FUSE: Finding File Upload Bugs via Penetration Testing.. In NDSS.","author":"Lee Taekjin","year":"2020","unstructured":"Taekjin Lee, Seongil Wi, Suyoung Lee, and Sooel Son. 2020. FUSE: Finding File Upload Bugs via Penetration Testing.. In NDSS."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516703"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468542"},{"key":"e_1_2_1_60_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Li Song","year":"2022","unstructured":"Song Li, Mingqing Kang, Jianwei Hou, and Yinzhi Cao. 2022. Mining Node.js Vulnerabilities via Object Dependence Graph and Query. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA. 143\u2013160. isbn:978-1-939133-31-1"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00062"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00121"},{"key":"e_1_2_1_63_1","unstructured":"Team Llama3. 2024. The Llama 3 Herd of Models. arxiv:2407.21783. arxiv:2407.21783"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559391"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/2566486.2568024"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3517414"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813680"},{"key":"e_1_2_1_68_1","unstructured":"OpenAI. 2023. GPT-4 Technical Report. arxiv:2303.08774"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_18"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133959"},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3649851"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645530"},{"key":"e_1_2_1_73_1","first-page":"31","volume-title":"Backporting Security Patches of Web Applications: A Prototype Design and Implementation on Injection Vulnerability Patches. In 31st USENIX Security Symposium (USENIX Security 22)","author":"Shi Youkun","year":"2022","unstructured":"Youkun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao, Yinzhi Cao, Ziwen Wang, Yudi Zhao, Zongan Huang, and Min Yang. 2022. Backporting Security Patches of Web Applications: A Prototype Design and Implementation on Injection Vulnerability Patches. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA. 1993\u20132010. isbn:978-1-939133-31-1"},{"key":"e_1_2_1_74_1","volume-title":"Exploring Same-Site Attacks in the Modern Web. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Squarcina Marco","year":"2021","unstructured":"Marco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara, and Matteo Maffei. 2021. Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern Web. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2917\u20132934. isbn:978-1-939133-24-3"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598116"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-80825-9_3"},{"key":"e_1_2_1_77_1","doi-asserted-by":"crossref","unstructured":"Avinash Sudhodanan Soheil Khodayari and Juan Caballero. 2020. Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks.","DOI":"10.14722\/ndss.2020.24278"},{"key":"e_1_2_1_78_1","volume-title":"A constraint-based method for flow-sensitive static type analysis Of PHP using the Rascal meta-programming platform","author":"Tamang Apil","unstructured":"Apil Tamang. 2015. A constraint-based method for flow-sensitive static type analysis Of PHP using the Rascal meta-programming platform. East Carolina University."},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607223"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179317"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW59333.2023.00038"},{"key":"e_1_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00198"}],"container-title":["Proceedings of the ACM on Programming Languages"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3720488","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3720488","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:08:53Z","timestamp":1760029733000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3720488"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,9]]},"references-count":82,"journal-issue":{"issue":"OOPSLA1","published-print":{"date-parts":[[2025,4,9]]}},"alternative-id":["10.1145\/3720488"],"URL":"https:\/\/doi.org\/10.1145\/3720488","relation":{},"ISSN":["2475-1421"],"issn-type":[{"value":"2475-1421","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,9]]},"assertion":[{"value":"2024-10-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-18","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}