Skip to content
Search
paperApril 2026Unreviewed

Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning

Ronghao Ni, Mihai Christodorescu, Limin Jia

Abstract

The rapidly evolving Node$.$js ecosystem currently includes millions of packages and is a critical part of modern software supply chains, making vulnerability detection of Node$.$js packages increasingly important. However, traditional program analysis struggles in this setting because of dynamic JavaScript features and the large number of package dependencies. Recent advances in large language models (LLMs) and the emerging paradigm of LLM-based agents offer an alternative to handcrafted progra

Categories

Framework mappings

MITRE ATLAS
  • AML.T0010AI Supply Chain Compromise

Suggested from the entry's categories.

Cite

@misc{ni2026taintstyle,
  title = {{Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning}},
  author = {Ronghao Ni and Mihai Christodorescu and Limin Jia},
  year = {2026},
  month = apr,
  eprint = {2604.20179},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2604.20179}
}