acceptodds
Under review as a conference paper at ICLR 2027

FORGE: FINDING AND ELIMINATING VULNERABILITIES WITH SOUND PROGRAM ANALYSIS

Abstract

LLM agents can discover and repair software vulnerabilities, but searching large codebases is costly and can leave exploitable bugs undiscovered. Static analysis can guide this search, yet practical analyzers often sacrifice coverage to limit false positives that burden human reviewers. We present FORGE, a system that revisits this tradeoff with an LLM agent performing triage. FORGE combines a conservative JavaScript/TypeScript analyzer with an agent that investigates candidate vulnerabilities, constructs executable reproductions, and repairs vulnerable code using analysis feedback. Across 15 large open-source repositories, FORGE finds 50% more vulnerabilities using just 18% of the model tokens of the next-best configuration. In a broader campaign, FORGE reproduced 176 vulnerabilities across 164 repositories, finding approximately 60% more non-race vulnerabilities than CodeQL-guided investigation and an additional 79 race and asynchronous-interleaving bugs. These findings included an unauthenticated remote code execution vulnerability in production code that was patched a day later. On six known real-world vulnerabilities, FORGE-guided repairs blocked every exploit in all five runs while consuming 23% fewer tokens than the unaided agent. These results demonstrate that conservative analysis can improve both the coverage and inference efficiency of agenticvulnerability discovery and repair.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.