PatchPorter: LLM-Driven Security Patch Porting via Version Tracing and Context Selection for NPM
Zeliang Yu, Ming Wen, Zichao Wei, Yulun Wu, Deqing Zou, Hai Jin
Abstract
Third-Party Libraries are widely used in modern software development, yet their vulnerabilities pose serious security risks. This issue is particularly severe in the NPM ecosystem, where high-risk 1-day vulnerabilities can remain unpatched for extended periods. Although upgrading to the latest patched version is commonly recommended, it often causes major compatibility issues. Patch porting offers an effective solution to this challenge. However, existing patch porting methods are mainly designed for C and have two limitations when applied to NPM. First, they can be brittle in precisely localizing fix locations when substantial semantic gaps exist across versions. Second, they rely on either excessive or insufficient context for patch adaptation, which may introduce redundant information and increase the risk of hallucination. This paper introduces PatchPorter, a method for single-branch security patch porting in NPM that builds on Large Language Models (LLMs). PatchPorter addresses these limitations through two modules. The localization module leverages LLM semantic understanding and code evolution analysis over version histories maintained by version control systems to identify fix locations. The context selection module analyzes patch dependencies to select minimal yet sufficient context around the localized fix location. The selected context is used as input for the LLM to generate the patch. We construct a dataset of 112 NPM vulnerabilities with Proof- of-Concepts for dynamic validation. Experimental results show that PatchPorter significantly surpasses other methods in accuracy, achieving a 26.23% improvement over the best-performing baseline and a 70.59% increase on the most difficult tasks. Its ability to handle various vulnerability types highlights its practical value. Additional results confirm that both of its main modules also outperform alternative approaches.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5bf08b89-698c-4156-859e-6d5b235e454dRelated papers
- LLMPort: Cross-file Patch Porting via Task Decomposition and Self-correctionBofei Chen, Lei Zhang, Peng Deng, Nan Wang et al.ASE 2025
- BackportBench: A Multilingual Benchmark for Automated Patch BackportingZhiqing Zhong, Jiaming Huang, Pinjia HeFSE 2026 · 1 citation
- Mystique: Automated Vulnerability Patch Porting with Semantic and Syntactic-Enhanced LLMSusheng Wu, Ruisi Wang, Yiheng Cao, Bihuan Chen et al.FSE 2025 · 2 citations
- LLMBisect: Breaking Barriers in Bug Bisection with A Comparative Analysis PipelineZheng Zhang, Haonan Li, Xingyu Li, Hang Zhang et al.NDSS 2026 · 1 citation
- Maltracker: A Fine-Grained NPM Malware Tracker Copiloted by LLM-Enhanced DatasetZeliang Yu, Ming Wen, Xiaochen Guo, Hai JinISSTA 2024 · 16 citations
