2 papers
cs.CR2026
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
Ronghao Ni, Mihai Christodorescu, Limin Jia
The rapidly evolving Nodejs ecosystem currently includes millions of packages and is a critical part of modern software supply chains, making vulnerability detection of Nodej…
cs.CR2025
Learning to Triage Vulnerability Reports from Program Analysis: An Empirical Study in Node.js
Ronghao Ni, Aidan Z. H. Yang, Min-Chien Hsu +5
Program analysis tools often produce large volumes of candidate vulnerability reports that require costly manual review, creating a practical challenge: how can security analysts p…