On the vulnerability proneness of multilingual code
Wen Li, Li Li, Haipeng Cai
Abstract
Software construction using multiple languages has long been a norm, yet it is still unclear if multilingual code construction has significant security implications and real security consequences. This paper aims to address this question with a large-scale study of popular multi-language projects on GitHub and their evolution histories, enabled by our novel techniques for multilingual code characterization. We found statistically significant associations between the proneness of multilingual code to vulnerabilities (in general and of specific categories) and its language selection. We also found this association is correlated with that of the language interfacing mechanism, not that of individual languages. We validated our statistical findings with in-depth case studies on actual vulnerabilities, explained via the mechanism and language selection. Our results call for immediate actions to assess and defend against multilingual vulnerabilities, for which we provide practical recommendations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0d9173d5-0c23-4fdd-8b8f-ffbc4e27b57dCited by top-tier papers7
- VGX: Large-Scale Sample Generation for Boosting Learning-Based Software Vulnerability AnalysesYu Nong, Richard Fang, Guangbei Yi, Kunsong Zhao et al.ICSE 2024 · 23 citations
- Generating realistic vulnerabilities via neural code editing: an empirical studyYu Nong, Yuzhe Ou, Michael Pradel, Feng Chen et al.FSE 2022 · 23 citations
- Demystifying Issues, Challenges, and Solutions for Multilingual Software DevelopmentHaoran Yang, Weile Lian, Shaowei Wang, Haipeng CaiICSE 2023 · 11 citations
- Learning to Detect and Localize Multilingual BugsHaoran Yang, Yu Nong, Tao Zhang, Xiapu Luo et al.FSE 2024 · 8 citations
- Finding Compiler Bugs through Cross-Language Code Generator and Differential TestingQiong Feng, Xiaotian Ma, Ziyuan Feng, Marat Akhin et al.OOPSLA 2025 · 2 citations
Builds on6
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen et al.CCS 2018 · 93 citations
- Broadening Horizons of Multilingual Static Analysis: Semantic Summary Extraction from C Code for JNI Program AnalysisSungho Lee, Hyogun Lee, Sukyoung RyuASE 2020 · 29 citations
- FlowDist: Multi-Staged Refinement-Based Dynamic Information Flow Analysis for Distributed Software SystemsXiaoqin Fu, Haipeng CaiUSENIX Security 2021 · 26 citations
- Generating realistic vulnerabilities via neural code editing: an empirical studyYu Nong, Yuzhe Ou, Michael Pradel, Feng Chen et al.FSE 2022 · 23 citations
- JUSTGen: Effective Test Generation for Unspecified JNI Behaviors on JVMsSungjae Hwang, Sungho Lee, Jihoon Kim, Sukyoung RyuICSE 2021 · 12 citations
Related papers
- Insight: Exploring Cross-Ecosystem Vulnerability ImpactsMeiqiu Xu, Ying Wang, Shing-Chi Cheung, Hai Yu et al.ASE 2022 · 12 citations
- Dissecting Real-World Cross-Language BugsHaoran Yang, Haipeng CaiFSE 2025 · 2 citations
- Diplomatist: What Do Cross-language Dependencies Reflect Software Ecosystem Health?Fanyi Meng, Ying Wang, Chun Yong Chong, Hai Yu et al.ASE 2025
- PolyFuzz: Holistic Greybox Fuzzing of Multi-Language SystemsWen Li, Jinyang Ruan, Guangbei Yi, Long Cheng et al.USENIX Security 2023
- “Write in English, Nobody Understands Your Language Here”: A Study of Non-English Trends in Open-Source RepositoriesMasudul Hasan Masud Bhuiyan, Manish Kumar Bala Kumar, Cristian-Alexandru StaicuICSE 2026 · 1 citation
