Collected research
NodeMedic-FINE: Automatic Detection and Exploit Synthesis for Node.js Vulnerabilities
NodeMedic-FINE pairs a type and object-structure aware fuzzer with dynamic taint tracking over npm packages, then uses the taint information to synthesise proof-of-concept exploits for arbitrary code execution and command injection sinks. Across 33,011 packages it found 2,257 candidate flows and produced working exploits for 766 of them.
Record
- Researcher
- Darion Cassel, Nuno Sabino, Min-Chien Hsu, Ruben Martins and Limin Jia
- Published by
- NDSS Symposium
- Topic
- Server
In the archive
Related sources
- NDSS 2025 - NodeMedic-FINE: Automatic Detection and Exploit Synthesis for Node.js Vulnerabilities
- NDSS 2025 - NodeMedic-FINE: Automatic Detection and Exploit Synthesis for Node.js Vulnerabilities
Tags
This page is the archive's own catalogue record. The research is the work of Darion Cassel, Nuno Sabino, Min-Chien Hsu, Ruben Martins and Limin Jia, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .