One Pipeline Does Not Fit All: TAILOR, a Type- and State-Aware Framework for CVE Reproduction

📅 2026-09-29
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the limitations of existing unified pipelines in accommodating the diverse execution requirements of CVEs and efficiently reproducing complex vulnerabilities. To this end, we propose TAILOR, a multi-agent framework that introduces a pioneering two-level awareness mechanism: a primary type-awareness level for matching execution paths, and a secondary state-awareness level for decoupling prerequisite state construction from core vulnerability triggering. By integrating static analysis transformation with web state construction techniques, TAILOR automatically converts static information into auditable reproduction evidence, thereby achieving end-to-end automated vulnerability reproduction. Evaluated on a dataset of 200 CVEs, the framework attains reproduction rates of 59.24% and 44.19% for web and traditional vulnerabilities, respectively, significantly broadening the coverage scope of automated vulnerability reproduction.
📝 Abstract
Growing vulnerability disclosure and widespread software reuse increase security teams' need for reproducible evidence to diagnose vulnerabilities, validate patches, and build regression tests. Producing such evidence at scale requires automated end-to-end CVE reproduction. Existing methods typically process different CVEs through a uniform pipeline, but differences in runtime form, trigger interfaces, and prerequisite state impose different execution requirements on individual stages, making fixed workflows difficult to adapt to diverse reproduction needs. To address this problem, we present TAILOR, a type- and state-aware multi-agent framework specialized for complex vulnerability reproduction. TAILOR converts static vulnerability information into auditable reproduction evidence and packages reconstructed environments and trigger evidence into reproduction artifacts. Its first-level type-aware mechanism adaptively matches each vulnerability to an execution path. Within the Web path, its second-level state-aware mechanism constructs the required prerequisite state before exploitation, decouples prerequisite-state construction from core vulnerability triggering, and shares execution constraints across exploitation and verification. We construct a dataset of 200 CVEs with an emphasis on cases with complex execution requirements. TAILOR successfully reproduces 59.24\% of Web vulnerabilities and 44.19\% of traditional vulnerabilities. Further ablation experiments show that the two control levels respectively mitigate execution-path mismatch and missing Web prerequisite state. Overall, TAILOR broadens the coverage of automated CVE reproduction and provides auditable evidence for vulnerability diagnosis and defense.
Problem

Research questions and friction points this paper is trying to address.

CVE reproduction
vulnerability diagnosis
automated exploitation
execution requirements
prerequisite state
Innovation

Methods, ideas, or system contributions that make the work stand out.

CVE Reproduction
Multi-agent Framework
Type-aware Mechanism
State-aware Mechanism
Vulnerability Artifacts
🔎 Similar Papers
No similar papers found.