Web Application Vulnerability Repair Via Context-Aware Fault Localization and Directed Differential Fuzzing
Chenlin Wang, Wei Meng
Abstract
Web applications handle sensitive data, yet exploitation of their vulnerabilities can cause significant losses due to their widespread use. While vulnerability detection techniques have become increasingly sophisticated, timely remediation remains challenging due to substantial manual effort requirements. Automated vulnerability repair has become increasingly mature, yet research targeting web applications remains limited due to challenges posed by dynamic languages like PHP, which powers 73.1 % of websites. Leveraging existing LLM-based repair work is non-trivial as these systems rely on specialized toolchains and readily available test suites that web applications rarely provide. We propose SlicePatch, a novel automated vulnerability repair framework for PHP web applications. SlicePatch leverages PoC-driven dynamic profiling to capture runtime program behavior and retain vulnerability-specific code paths in a context-aware manner. The isolated vulnerable code slices, distilled from the broader application codebase, guide LLMs to generate precise patches while cutting invocation cost. We pioneer directed differential fuzzing that helps validate and refine patch candidates iteratively without requiring test suites. Our extensive evaluation across 96 real-world vulnerabilities and LLMs shows that SlicePatch attains a repair success rate, significantly outperforming baselines by over .
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter AnalysisPenghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang et al.S&P 2024 · 6 citations
- Well Begun is Half Done: Location-Aware and Trace-Guided Iterative Automated Vulnerability RepairZhenlei Ye, Xiaobing Sun, Sicong Cao, Lili Bo et al.ICSE 2026
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
- Predator: Directed Web Application Fuzzing for Efficient Vulnerability ValidationChenlin Wang, Wei Meng, Changhua Luo, Penghui LiS&P 2025
- XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent FuzzingYoukun Shi, Yuan Zhang, Tianhao Bai, Feng Xue et al.USENIX Security 2025
