Skip to content
Search
paper2024ReviewedOpen access

LLM Agents Can Autonomously Exploit One-day Vulnerabilities

Richard Fang, Rohan Bindu, Akul Gupta, Daniel Kang

arXiv preprint

Abstract

Shows that LLM agents (GPT-4) can autonomously exploit real-world one-day vulnerabilities given CVE descriptions, achieving 87% success rate.

Categories

#autonomous-exploit#CVE#one-day#offensive

Framework mappings

OWASP Top 10 for Agentic Applications
  • ASI03Agent Identity & Privilege Abuse
  • ASI10Rogue Agents

Cite

@misc{fang2024llmb,
  title = {{LLM Agents Can Autonomously Exploit One-day Vulnerabilities}},
  author = {Richard Fang and Rohan Bindu and Akul Gupta and Daniel Kang},
  year = {2024},
  eprint = {2404.08144},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2404.08144}
}