May 2026Unreviewed
Correct Code, Vulnerable Dependencies: A Large Scale Measurement Study of LLM-Specified Library Versions
Chengjie Wang, Jingzheng Wu, Xiang Ling, Tianyue Luo, Chen Zhao
Abstract
Large language models (LLMs) are now largely involved in software development workflows, and the code they generate routinely includes third-party library (TPL) imports annotated with specific version identifiers. These version choices can carry security and compatibility risks, yet they have not been systematically studied. We present the first large-scale measurement study of version-level risk in LLM-generated Python code, evaluating 10 LLMs on PinTrace, a curated benchmark of 1,000 Stack Ove
Categories
Cite
@misc{wang2026correct,
title = {{Correct Code, Vulnerable Dependencies: A Large Scale Measurement Study of LLM-Specified Library Versions}},
author = {Chengjie Wang and Jingzheng Wu and Xiang Ling and Tianyue Luo and Chen Zhao},
year = {2026},
month = may,
eprint = {2605.06279},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.06279}
}