VulnRep: Reproducer-Verified LLM-Based Vulnerability Discovery

Authors: Mischa Meier, Annika Kuntze, Veit Eysholdt, Christoph Geron, Maxim Shevchishin, Niklas Steffen, Maximilian Leiwig, Julian Steffen, Felix Boes, Matthew Smith, Sergej Dechand

Venue: Detection of Intrusions and Malware, and Vulnerability Assessment - 23rd International Conference, DIMVA 2026, Chania, Greece, July 1-3, 2026, Proceedings

Series: Lecture Notes in Computer Science

Publisher: Springer

Year: 2026

LLM-based vulnerability discovery is often tied to commercial APIs and large compute infrastructure, which rules it out for teams that cannot send their code to external providers. Our DIMVA 2026 paper introduces VulnRep, a lightweight multi-agent Cyber Reasoning System designed to work across the model capability spectrum, from frontier commercial models down to open-weight models that run on premise on consumer hardware.

VulnRep unifies LLM-driven static analysis with dynamic verification: an Analyzer agent explores code at the symbol level via the Language Server Protocol and identifies potential vulnerabilities, and a Verifier agent confirms them by constructing reproducers that trigger sanitizers from existing harnesses, which eliminates false positives for sanitizer-detectable bug classes.

We evaluate VulnRep on 14 vulnerabilities from the AIxCC nginx challenge, reproduce 11 of 64 real-world OSS-Fuzz issues, and analyze 82 active open-source projects, uncovering 2 previously undocumented issues in mature systems.

Proprietary models achieve the highest success rates, but strong open-weight models still reproduce several vulnerabilities, making fully local, self-hosted vulnerability discovery viable when some reduction in effectiveness is acceptable.