{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T03:23:07Z","timestamp":1785381787481,"version":"3.55.0"},"reference-count":70,"publisher":"Association for Computing Machinery (ACM)","issue":"PLDI","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Program. Lang."],"published-print":{"date-parts":[[2025,6,10]]},"abstract":"<jats:p>The Node.js ecosystem, with its growing popularity and increasing exposure to security vulnerabilities, has a pressing need for more effective security analysis tools. To reduce false positives, recent works on detecting vulnerabilities in Node.js packages have developed synthesis algorithms to generate proof-of-concept exploits. However, these tools focus mainly on vulnerabilities that can be triggered by a single direct call to an exported function of the analyzed package, failing to generate exploits that require more complex interactions.<\/jats:p>\n                  <jats:p>\n                    In this paper, we present\n                    <jats:sc>Explode.js<\/jats:sc>\n                    , the first tool capable of synthesizing exploits that include complex call sequences to trigger vulnerabilities in Node.js packages. By combining static analysis and symbolic execution,\n                    <jats:sc>Explode.js<\/jats:sc>\n                    generates functional exploits that confirm the existence of command, code injection, prototype pollution, and path traversal vulnerabilities, effectively eliminating false positives. The results of evaluating\n                    <jats:sc>Explode.js<\/jats:sc>\n                    on two state-of-the-art datasets of Node.js packages with confirmed vulnerabilities show that it generates significantly more exploits than its main competitor tools. Furthermore, when applied to real-world Node.js packages,\n                    <jats:sc>Explode.js<\/jats:sc>\n                    uncovered 44 zero-day vulnerabilities, with 4 new CVEs.\n                  <\/jats:p>","DOI":"10.1145\/3729304","type":"journal-article","created":{"date-parts":[[2025,6,13]],"date-time":"2025-06-13T16:02:27Z","timestamp":1749830547000},"page":"1341-1366","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Automated Exploit Generation for Node.js Packages"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2555-5382","authenticated-orcid":false,"given":"Filipe","family":"Marques","sequence":"first","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico, Universidade de Lisboa, Lisboa, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5307-4279","authenticated-orcid":false,"given":"Mafalda","family":"Ferreira","sequence":"additional","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico, Universidade de Lisboa, Lisboa, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0043-3613","authenticated-orcid":false,"given":"Andr\u00e9","family":"Nascimento","sequence":"additional","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico, Universidade de Lisboa, Lisboa, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7191-5895","authenticated-orcid":false,"given":"Miguel E.","family":"Coimbra","sequence":"additional","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico, Universidade de Lisboa, Lisboa, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9938-0653","authenticated-orcid":false,"given":"Nuno","family":"Santos","sequence":"additional","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico, Universidade de Lisboa, Lisboa, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8160-349X","authenticated-orcid":false,"given":"Limin","family":"Jia","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University, Pittsburgh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5077-300X","authenticated-orcid":false,"given":"Jos\u00e9","family":"Fragoso Santos","sequence":"additional","affiliation":[{"name":"INESC-ID, Lisboa, Portugal"},{"name":"Instituto Superior T\u00e9cnico, Universidade de Lisboa, Lisboa, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,13]]},"reference":[{"key":"e_1_3_2_2_2","first-page":"377","volume-title":"Proceedings of the 27th USENIX Security Symposium (SEC\u201918)","author":"Alhuzali Abeer","year":"2018","unstructured":"Abeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, and V. N. Venkatakrishnan. 2018. NAVEX: Precise and Scalable Exploit Generation for Dynamic Web Applications. In Proceedings of the 27th USENIX Security Symposium (SEC\u201918). USENIX Association, Baltimore, MD, 377\u2013392."},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-71209-1_12"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10009-008-0090-1"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.22152\/programming-journal.org\/2025\/9\/3"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","unstructured":"Vaggelis Atlidakis Patrice Godefroid and Marina Polishchuk. 2019. RESTler: Stateful REST API Fuzzing. In Proceedings of the 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE\u201919). 748\u2013758. doi:10.1109\/ICSE.2019.00083","DOI":"10.1109\/ICSE.2019.00083"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3340456"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3182657"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447852.3458718"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","unstructured":"Masudul Hasan Masud Bhuiyan Adithya Srinivas Parthasarathy Nikos Vasilakis Michael Pradel and Cristian-Alexandru Staicu. 2023. SecBench.js: An Executable Security Benchmark Suite for Server-Side JavaScript. In Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE\u201923). 1059\u20131070. doi:10.1109\/ICSE48619.2023.00096","DOI":"10.1109\/ICSE48619.2023.00096"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2023.3286301"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102745"},{"key":"e_1_3_2_13_2","first-page":"199","volume-title":"Proceedings of the 29th USENIX Conference on Security Symposium (SEC\u201920)","author":"Brown Fraser","year":"2020","unstructured":"Fraser Brown, Deian Stefan, and Dawson Engler. 2020. Sys: a static\/symbolic tool for finding good bugs in good (browser) code. In Proceedings of the 29th USENIX Conference on Security Symposium (SEC\u201920). USENIX Association, USA, 199\u2013216."},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.5555\/1855741.1855756"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180445"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","unstructured":"Darion Cassel Nuno Sabino Min-Chien Hsu Ruben Martins and Limin Jia. 2025. NODEMEDIC-FINE: Automatic Detection and Exploit Synthesis for Node.js Vulnerabilities. In Proceedings of the 2025 Network and Distributed System Security Symposium (NDSS\u201925). doi:10.14722\/ndss.2025.241636","DOI":"10.14722\/ndss.2025.241636"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","unstructured":"Darion Cassel Wai Tuck Wong and Limin Jia. 2023. NodeMedic: End-to-End Analysis of Node.js Vulnerabilities with Provenance Graphs. In Proceedings of the 2023 European Symposium on Security and Privacy (EuroS&P\u201923). 1101\u20131127. doi:10.1109\/EuroSP57164.2023.00068","DOI":"10.1109\/EuroSP57164.2023.00068"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.5555\/1792734.1792766"},{"key":"e_1_3_2_19_2","unstructured":"Devon Govett and Parcel contributors. 2021. Parcel \u2013 The zero configuration build tool for the web. https:\/\/parceljs.orgvisited on 2024-11-11."},{"key":"e_1_3_2_20_2","unstructured":"ECMA International. 2025. ECMAScript\u00ae 2025 Language Specification. https:\/\/tc39.es\/ecma262\/ visisted on 2025-03-25."},{"key":"e_1_3_2_21_2","unstructured":"Chris Eppstein Scott Davis Miriam Suzanne Brandon Mathis and Nico Hagenburger. 2024. Compass Stylesheet Authoring Framework. https:\/\/github.com\/Compass\/compass visited on 2024-11-13."},{"key":"e_1_3_2_22_2","unstructured":"Evan Wallace. 2020. esbuild - An extremely fast bundler for the web. https:\/\/esbuild.github.io\/ visited on 2024-11-11."},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179395"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3656394"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3385412.3386014"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236950.3236956"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3290379"},{"key":"e_1_3_2_28_2","volume-title":"HIJaX: Human Intent to Javascript XSS Generator. PhD Thesis","author":"Frempong Yaw","year":"2022","unstructured":"Yaw Frempong. 2022. HIJaX: Human Intent to Javascript XSS Generator. PhD Thesis. The University of North Carolina at Charlotte. http:\/\/ninercommons.charlotte.edu\/record\/2205"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274723"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236454.3236502"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065036"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/2093548.2093564"},{"key":"e_1_3_2_33_2","unstructured":"Google. 2008. V8 JavaScript Engine. https:\/\/chromium.googlesource.com\/v8\/v8.git visited on 2024-11-13."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","unstructured":"Harrison Green and Thanassis Avgerinos. 2022. GraphFuzz: Library API Fuzzing with Lifetime-aware Dataflow Graphs. In Proceedings of the 2022 IEEE\/ACM 44th International Conference on Software Engineering (ICSE\u201922). 1070\u20131081. doi:10.1145\/3510003.3510228 ISSN: 1558-1225.","DOI":"10.1145\/3510003.3510228"},{"key":"e_1_3_2_35_2","unstructured":"Kyriakos Ispoglou Daniel Austin Vishwath Mohan and Mathias Payer. 2020. FuzzGen: Automatic Fuzzer Generation. In Proceedings of the 29th USENIX Security Symposium (SEC\u201920). 2271\u20132287."},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/1529282.1529711"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","unstructured":"Mingqing Kang Yichao Xu Song Li Rigel Gjomemo Jianwei Hou V. N. Venkatakrishnan and Yinzhi Cao. 2023. Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style Vulnerability. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP\u201923). 1059\u20131076. doi:10.1109\/SP46215.2023.10179352","DOI":"10.1109\/SP46215.2023.10179352"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","unstructured":"Rezwana Karim Frank Tip Alena Soch\u016frkov\u00e1 and Koushik Sen. 2020. Platform-Independent Dynamic Taint Analysis for JavaScript. IEEE Transactions on Software Engineering 46 12 (2020) 1364\u20131379. doi:10.1109\/TSE.2018.2878020","DOI":"10.1109\/TSE.2018.2878020"},{"key":"e_1_3_2_39_2","first-page":"2525","volume-title":"Proceedings of the 30th USENIX Security Symposium (SEC\u201921)","author":"Khodayari Soheil","year":"2021","unstructured":"Soheil Khodayari and Giancarlo Pellegrino. 2021. JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative Traversals. In Proceedings of the 30th USENIX Security Symposium (SEC\u201921). USENIX Association, Boston, MA, 2525\u20132542."},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36577-X_40"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516703"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635913"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-018-0002-y"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/2483760.2483778"},{"key":"e_1_3_2_45_2","first-page":"143","volume-title":"Proceedings of the 31st USENIX Security Symposium (SEC\u201922)","author":"Li Song","year":"2022","unstructured":"Song Li, Mingqing Kang, Jianwei Hou, and Yinzhi Cao. 2022. Mining Node.js Vulnerabilities via Object Dependence Graph and Query. In Proceedings of the 31st USENIX Security Symposium (SEC\u201922). USENIX Association, Boston, MA, 143\u2013160."},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3092282.3092295"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2946563"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","unstructured":"Filipe Marques Mafalda Ferreira Andr\u00e9 Nascimento Miguel E. Coimbra Nuno Santos Limin Jia and Jos\u00e9 Fragoso Santos. 2025. Automated Exploit Generation for Node.js Packages. doi:10.5281\/zenodo.15225072","DOI":"10.5281\/zenodo.15225072"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2022.11"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23309"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338933"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","unstructured":"Carlos Pacheco Shuvendu K. Lahiri Michael D. Ernst and Thomas Ball. 2007. Feedback-Directed Random Test Generation. In 29th International Conference on Software Engineering (ICSE\u201907). 75\u201384. doi:10.1109\/ICSE.2007.37","DOI":"10.1109\/ICSE.2007.37"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2803191"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133959"},{"key":"e_1_3_2_55_2","unstructured":"Jo\u00e3o Madeira Pereira Filipe Marques Pedro Ad\u00e3o Hichem Rami Ait El Hara L\u00e9o Andr\u00e8s Arthur Carcano Pierre Chambart Nuno Santos and Jos\u00e9 Fragoso Santos. 2024. Smt.ml: A Multi-Backend Frontend for SMT Solvers in OCaml. (2024). https:\/\/inria.hal.science\/hal-04761767"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2023.24"},{"key":"e_1_3_2_57_2","unstructured":"Ryan Dahl and OpenJS Foundation. 2009. Node.js JavaScript Runtime. https:\/\/github.com\/nodejs\/node visited on 2014-11-13."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2020.28"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/2491411.2494598"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2786830"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24610"},{"key":"e_1_3_2_62_2","first-page":"361","volume-title":"Proceedings of the 27th USENIX Security Symposium (SEC\u201918)","author":"Staicu Cristian-Alexandru","year":"2018","unstructured":"Cristian-Alexandru Staicu and Michael Pradel. 2018. Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web Servers. In Proceedings of the 27th USENIX Security Symposium (SEC\u201918). USENIX Association, Baltimore, MD, 361\u2013376."},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23071"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417267"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23368"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3689733"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453483.3454084"},{"key":"e_1_3_2_68_2","unstructured":"Tobias Koppers Sean Larkin Johannes Ewald Juho Veps\u00e4l\u00e4inen Kees Kluskens and Webpack contributors. 2014. Webpack Bundler. https:\/\/webpack.js.org\/ visited on 2024-11-11."},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","unstructured":"Fish Wang and Yan Shoshitaishvili. 2017. Angr - The Next Generation of Binary Analysis. In 2017 IEEE Cybersecurity Development (SecDev\u201917). 8\u20139. doi:10.1109\/SecDev.2017.14","DOI":"10.1109\/SecDev.2017.14"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2989171"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.44"}],"container-title":["Proceedings of the ACM on Programming Languages"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3729304","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T10:02:03Z","timestamp":1784196123000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3729304"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,10]]},"references-count":70,"journal-issue":{"issue":"PLDI","published-print":{"date-parts":[[2025,6,10]]}},"alternative-id":["10.1145\/3729304"],"URL":"https:\/\/doi.org\/10.1145\/3729304","relation":{},"ISSN":["2475-1421"],"issn-type":[{"value":"2475-1421","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,10]]},"assertion":[{"value":"2024-11-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-03-06","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-06-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}