CrossPloit: Can LLM Agents Migrate Exploits Across Software Versions?
Abstract
Cross-version proof-of-concept (PoC) migration requires an agent to adapt a working exploit to another software version while preserving the underlying vulnerability. The task combines source-code analysis, environment repair, and execution-based verification. We introduce CrossPloit, a benchmark of 127 migration instances across 45 CVEs in the Python web ecosystem. Each instance includes a version-pinned container, a reference PoC, and a vulnerability-specific oracle; two validators check that the observed effect arises from the disclosed vulnerability. Across 18 agent configurations (nine models and two harnesses), the best configuration resolves 58.3% of instances, compared with 8.7% for an adapted trace-guided baseline. Attack-vector shifts are particularly difficult: no configuration resolves more than 37.9% of these instances. Higher resolve rates are associated with a smaller share of missed-API failures and a larger share of incomplete executions among the remaining failures. In one configuration, withholding the reference PoC and its environment specification reduces resolve rate from 50.4% to 15.0%, highlighting the value of the supplied reference package. CrossPloit provides an execution-based evaluation of agents' ability to preserve exploit semantics across software versions.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.