Diffploit: Facilitating Cross-Version Exploit Migration for Open Source Library Vulnerabilities
Zirui Chen, Zhipeng Xue, Jiayuan Zhou, Xing Hu, Xin Xia, Xiaohu Yang
Abstract
Exploits are commonly used to demonstrate the presence of library vulnerabilities and validate their impact across different versions. However, their direct application to alternative versions often fails due to breaking changes introduced during evolution. These failures stem from both changes in triggering conditions (e.g., API refactorings) and broken dynamic environments (e.g., build or runtime errors), which are challenging to interpret and adapt manually. Existing techniques primarily focus on code-level trace alignment through fuzzing, which is both time-consuming and insufficient for handling environment-level failures. Moreover, they often fall short when dealing with complicated triggering condition changes across versions. To overcome this, we propose Diffploit, an iterative, diff-driven exploit migration method structured around two key modules: the Context Module and the Migration Module. The Context Module constructs contexts derived from analyzing behavioral discrepancies between the target and reference versions, which capture the failure symptom and its related diff hunks. Leveraging these contexts, the Migration Module guides an LLM-based adaptation through an iterative feedback loop, balancing exploration of diff candidates and gradual refinement to resolve reproduction failures effectively. We evaluate Diffploit on a large-scale dataset containing 102 Java CVEs and 689 version-migration tasks across 79 libraries. Diffploit successfully migrates 84.2% exploits, outperforming the change-aware test repair tool TaRGET by 52.0% and the rule-based tool in IDEA by 61.6%. Beyond technical effectiveness, Diffploit identifies 5 CVE reports with incorrect affected version ranges, three of which have been confirmed. We also discover 111 unreported versions in GitHub Advisory Database.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0d4f6ef6-adc2-435b-9380-e0846221b5a8Cited by top-tier papers2
- Depradar: Agentic Coordination for Context-Aware Defect Impact Analysis in Deep Learning LibrariesYi Gao, Xing Hu, Tongtong Xu, Jiali Zhao et al.ICSE 2026
- CREME: Robustness Enhancement of Code LLMs via Layer-Aware Model EditingShuhan Liu, Xing Hu, Kerui Huang, Xiaohu Yang et al.ICSE 2026
Builds on34
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing et al.USENIX Security 2019 · 149 citations
- Data Quality for Software Vulnerability DatasetsRoland Croft, Muhammad Ali Babar, M. Mehdi KholoosiICSE 2023 · 138 citations
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu et al.USENIX Security 2018 · 138 citations
Related papers
- AEM: Facilitating Cross-Version Exploitability Assessment of Linux Kernel VulnerabilitiesZheyue Jiang, Yuan Zhang, Jun Xu, Xinqian Sun et al.S&P 2023
- Exploiting Library Vulnerability via Migration Based Automating Test GenerationZirui Chen, Xing Hu, Xin Xia, Yi Gao et al.ICSE 2024 · 10 citations
- Facilitating Vulnerability Assessment through PoC MigrationJiarun Dai, Yuan Zhang, Hailong Xu, Haiming Lyu et al.CCS 2021 · 26 citations
- LLMPort: Cross-file Patch Porting via Task Decomposition and Self-correctionBofei Chen, Lei Zhang, Peng Deng, Nan Wang et al.ASE 2025
- Well Begun is Half Done: Location-Aware and Trace-Guided Iterative Automated Vulnerability RepairZhenlei Ye, Xiaobing Sun, Sicong Cao, Lili Bo et al.ICSE 2026
