April 2026Unreviewed
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
Ronghao Ni, Mihai Christodorescu, Limin Jia
Abstract
The rapidly evolving Node$.$js ecosystem currently includes millions of packages and is a critical part of modern software supply chains, making vulnerability detection of Node$.$js packages increasingly important. However, traditional program analysis struggles in this setting because of dynamic JavaScript features and the large number of package dependencies. Recent advances in large language models (LLMs) and the emerging paradigm of LLM-based agents offer an alternative to handcrafted progra
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM03Supply Chain
MITRE ATLAS
- AML.T0010AI Supply Chain Compromise
Suggested from the entry's categories.
Cite
@misc{ni2026taintstyle,
title = {{Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning}},
author = {Ronghao Ni and Mihai Christodorescu and Limin Jia},
year = {2026},
month = apr,
eprint = {2604.20179},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.20179}
}