← Back to search
paper llmsec-2026-00082

Correct Code, Vulnerable Dependencies: A Large Scale Measurement Study of LLM-Specified Library Versions

Chengjie Wang, Jingzheng Wu, Xiang Ling, Tianyue Luo, Chen Zhao

2026-05

Abstract

Large language models (LLMs) are now largely involved in software development workflows, and the code they generate routinely includes third-party library (TPL) imports annotated with specific version identifiers. These version choices can carry security and compatibility risks, yet they have not been systematically studied. We present the first large-scale measurement study of version-level risk in LLM-generated Python code, evaluating 10 LLMs on PinTrace, a curated benchmark of 1,000 Stack Ove

Categories

Cite This Resource

@article{llmsec202600082,
  title = {Correct Code, Vulnerable Dependencies: A Large Scale Measurement Study of LLM-Specified Library Versions},
  author = {Chengjie Wang and Jingzheng Wu and Xiang Ling and Tianyue Luo and Chen Zhao},
  year = {2026},
  url = {https://arxiv.org/abs/2605.06279},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.06279