{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:07:06Z","timestamp":1784300826330,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,7,5]],"date-time":"2026-07-05T00:00:00Z","timestamp":1783209600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,7,5]]},"DOI":"10.1145\/3803437.3805532","type":"proceedings-article","created":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:27:39Z","timestamp":1784298459000},"page":"1565-1572","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-9305-5961","authenticated-orcid":false,"given":"Fariha Tanjim","family":"Shifat","sequence":"first","affiliation":[{"name":"Missouri University of Science and Technology, Rolla, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-4663-8112","authenticated-orcid":false,"given":"Hariswar","family":"Baburaj","sequence":"additional","affiliation":[{"name":"Missouri University of Science and Technology, Rolla, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8441-6000","authenticated-orcid":false,"given":"Ce","family":"Zhou","sequence":"additional","affiliation":[{"name":"Missouri University of Science and Technology, Rolla, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6440-7596","authenticated-orcid":false,"given":"Jaydeb","family":"Sarker","sequence":"additional","affiliation":[{"name":"University of Nebraska Omaha, Omaha, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2477-9971","authenticated-orcid":false,"given":"Mia Mohammad","family":"Imran","sequence":"additional","affiliation":[{"name":"Missouri University of Science and Technology, Rolla, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,17]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2026. GHSA-2vv2-3x8x-4gv7. https:\/\/github.com\/advisories\/GHSA-2vv2-3x8x-4gv7."},{"key":"e_1_3_2_1_2_1","unstructured":"2026. GHSA-3ch2-jxxc-v4xf. https:\/\/github.com\/advisories\/GHSA-3ch2-jxxc-v4xf."},{"key":"e_1_3_2_1_3_1","unstructured":"2026. GHSA-6f6r-m9pv-67jw. https:\/\/github.com\/advisories\/GHSA-6f6r-m9pv-67jw."},{"key":"e_1_3_2_1_4_1","unstructured":"2026. GHSA-6fvq-23cw-5628. https:\/\/github.com\/advisories\/GHSA-6fvq-23cw-5628."},{"key":"e_1_3_2_1_5_1","unstructured":"2026. GHSA-793v-gxfp-9q9h. https:\/\/github.com\/advisories\/GHSA-793v-gxfp-9q9h."},{"key":"e_1_3_2_1_6_1","unstructured":"2026. GHSA-7944-7c6r-55vv. https:\/\/github.com\/advisories\/GHSA-7944-7c6r-55vv."},{"key":"e_1_3_2_1_7_1","unstructured":"2026. GHSA-8r9q-7v3j-jr4g. https:\/\/github.com\/advisories\/GHSA-8r9q-7v3j-jr4g."},{"key":"e_1_3_2_1_8_1","unstructured":"2026. GHSA-hf3c-wxg2-49q9. https:\/\/github.com\/advisories\/GHSA-hf3c-wxg2-49q9."},{"key":"e_1_3_2_1_9_1","unstructured":"2026. GHSA-hfcf-79gh-f3jc. https:\/\/github.com\/advisories\/GHSA-hfcf-79gh-f3jc."},{"key":"e_1_3_2_1_10_1","unstructured":"2026. GHSA-j9g7-mqhh-9hxf. https:\/\/github.com\/advisories\/GHSA-j9g7-mqhh-9hxf."},{"key":"e_1_3_2_1_11_1","unstructured":"2026. GHSA-jmgm-gx32-vp4w. https:\/\/github.com\/advisories\/GHSA-jmgm-gx32-vp4w."},{"key":"e_1_3_2_1_12_1","unstructured":"2026. GHSA-mrw7-hf4f-83pf. https:\/\/github.com\/advisories\/GHSA-mrw7-hf4f-83pf."},{"key":"e_1_3_2_1_13_1","unstructured":"2026. GHSA-xq4m-mc3c-vvg3. https:\/\/github.com\/advisories\/GHSA-xq4m-mc3c-vvg3."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10278-4"},{"key":"e_1_3_2_1_15_1","volume-title":"Thematic analysis. The journal of positive psychology 12, 3","author":"Clarke Victoria","year":"2017","unstructured":"Victoria Clarke and Virginia Braun. 2017. Thematic analysis. The journal of positive psychology 12, 3 (2017), 297\u2013298."},{"key":"e_1_3_2_1_16_1","volume-title":"A Coefficient of Agreement for Nominal Scales. Educational and Psychological Measurement","author":"Cohen Jacob","year":"1960","unstructured":"Jacob Cohen. 1960. A Coefficient of Agreement for Nominal Scales. Educational and Psychological Measurement (1960)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196398.3196401"},{"key":"e_1_3_2_1_18_1","volume-title":"From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows","author":"Ferrag Mohamed Amine","year":"2025","unstructured":"Mohamed Amine Ferrag, Norbert Tihanyi, Djallel Hamouda, Leandros Maglaras, Abderrahmane Lakas, and Merouane Debbah. 2025. From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows. ICT Express (2025)."},{"key":"e_1_3_2_1_19_1","unstructured":"GitHub Inc. 2026. GitHub Advisory Database. https:\/\/github.com\/advisories."},{"key":"e_1_3_2_1_20_1","unstructured":"GitHub Inc. 2026. GitHub Security Advisories. https:\/\/docs.github.com\/en\/code-security\/concepts\/vulnerability-reporting-and-management\/about-repository-security-advisories."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00135"},{"key":"e_1_3_2_1_23_1","unstructured":"Kilem L Gwet. 2014. Handbook of inter-rater reliability: The definitive guide to measuring the extent of agreement among raters. Advanced Analytics LLC."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3712003"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3695988"},{"key":"e_1_3_2_1_26_1","volume-title":"Understanding Large Language Model Supply Chain: Structure, Domain, and Vulnerabilities. arXiv preprint arXiv:2504.20763","author":"Hu Yanzhe","year":"2025","unstructured":"Yanzhe Hu, Shenao Wang, Tianyuan Nie, Yanjie Zhao, and Haoyu Wang. 2025. Understanding Large Language Model Supply Chain: Structure, Domain, and Vulnerabilities. arXiv preprint arXiv:2504.20763 (2025)."},{"key":"e_1_3_2_1_27_1","volume-title":"Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain. arXiv preprint arXiv:2410.21218","author":"Huang Kaifeng","year":"2024","unstructured":"Kaifeng Huang, Bihuan Chen, You Lu, Susheng Wu, Dingji Wang, Yiheng Huang, Haowen Jiang, Zhuotong Zhou, Junming Cao, and Xin Peng. 2024. Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain. arXiv preprint arXiv:2410.21218 (2024)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3716822"},{"key":"e_1_3_2_1_29_1","unstructured":"Yi Liu Gelei Deng Yuekang Li Kailong Wang Zihao Wang Xiaofeng Wang Tianwei Zhang Yepang Liu Haoyu Wang Yan Zheng et al. 2023. Prompt injection attack against llm-integrated applications. arXiv preprint arXiv:2306.05499 (2023)."},{"key":"e_1_3_2_1_30_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Liu Yupei","year":"2024","unstructured":"Yupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia, and Neil Zhenqiang Gong. 2024. Formalizing and benchmarking prompt injection attacks and defenses. In 33rd USENIX Security Symposium (USENIX Security 24). 1831\u20131847."},{"key":"e_1_3_2_1_31_1","unstructured":"MITRE. [n. d.]. Common Weakness Enumeration (CWE). https:\/\/cwe.mitre.org."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"e_1_3_2_1_33_1","volume-title":"OWASP Top 10 for LLM Applications","author":"Foundation OWASP","year":"2025","unstructured":"OWASP Foundation. 2025. OWASP Top 10 for LLM Applications 2025. Open Web Application Security Project (OWASP). https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/ Version 2025, OWASP Top 10 for Large Language Model Applications; latest edition outlining the ten most critical security risks in LLM applications.."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-020-09830-x"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2997"},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the 23rd International Conference on Mining Software Repositories (MSR","author":"Segal Claudio","year":"2026","unstructured":"Claudio Segal, Paulo Segal, Carlos Eduardo de Schuller Banjar, Felipe Paix\u00e3o, Hudson Silva Borges, Paulo Silveira Neto, Eduardo Santana de Almeida, Joanna Santos, Anton Kocheturov, Gaurav Kumar Srivastava, et al. 2026. Characterizing and Modeling the GitHub Security Advisories Review Pipeline. In Proceedings of the 23rd International Conference on Mining Software Repositories (MSR 2026). ACM, Rio de Janeiro, Brazil."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","unstructured":"Fariha Tanjim Shifat Hariswar Baburaj Ce Zhou Jaydeb Sarker and Mia Mohammad Imran. 2026. Replication Package for: LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories. 10.5281\/zenodo.18686343","DOI":"10.5281\/zenodo.18686343"},{"key":"e_1_3_2_1_38_1","volume-title":"Jingsen Zhang, Zhi-Yang Chen, Jiakai Tang, Xu Chen, Yankai Lin, Wayne Xin Zhao, Zhewei Wei, and Ji rong Wen.","author":"Wang Lei","year":"2023","unstructured":"Lei Wang, Chengbang Ma, Xueyang Feng, Zeyu Zhang, Hao ran Yang, Jingsen Zhang, Zhi-Yang Chen, Jiakai Tang, Xu Chen, Yankai Lin, Wayne Xin Zhao, Zhewei Wei, and Ji rong Wen. 2023. A survey on large language model based autonomous agents. Frontiers of Computer Science 18 (2023). https:\/\/api.semanticscholar.org\/CorpusID:261064713"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3708531"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-024-4222-0"},{"key":"e_1_3_2_1_41_1","volume-title":"ICLR 2023. All rights reserved.; 11th International Conference on Learning Representations, ICLR 2023 ; Conference date: 01-05-2023 Through 05-05-2023","author":"Yao Shunyu","year":"2023","unstructured":"Shunyu Yao, Jeffrey Zhao, Dian Yu, Nan Du, Izhak Shafran, Karthik Narasimhan, and Yuan Cao. 2023. REACT: SYNERGIZING REASONING AND ACTINGINLAN-GUAGE MODELS. Publisher Copyright: \u00a9 2023 11th International Conference on Learning Representations, ICLR 2023. All rights reserved.; 11th International Conference on Learning Representations, ICLR 2023 ; Conference date: 01-05-2023 Through 05-05-2023."},{"key":"e_1_3_2_1_42_1","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security). USENIX Association, 995\u20131010","author":"Zimmermann Markus","year":"2019","unstructured":"Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019. Small World with High Risks: A Study of Security Threats in the npm Ecosystem. In Proceedings of the 28th USENIX Security Symposium (USENIX Security). USENIX Association, 995\u20131010."}],"event":{"name":"FSE Companion '26: 34th ACM International Conference on the Foundations of Software Engineering","location":"Concordia University Montreal QC Canada","acronym":"FSE Companion '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3803437.3805532","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T14:35:46Z","timestamp":1784298946000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3803437.3805532"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,5]]},"references-count":42,"alternative-id":["10.1145\/3803437.3805532","10.1145\/3803437"],"URL":"https:\/\/doi.org\/10.1145\/3803437.3805532","relation":{},"subject":[],"published":{"date-parts":[[2026,7,5]]},"assertion":[{"value":"2026-07-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}