🚀NEW COURSEVibe Coding AI Apps with Claude Code 🤖✨Enroll now
← All papers  /  Sep 21, 2026
Agents · Evaluation

Vulnerability Localization Benchmark: Measuring Agentic Security Analysis at Repository Scale

First page
Vulnerability Localization Benchmark: Measuring Agentic Security Analysis at Repository Scale
The curator’s take

Aman Priyanshu and colleagues at Cisco Foundation AI introduce VLoc Bench, which tests whether agents can find the files affected by a known weakness class in an unfamiliar repository, and whether they can recognize that a patched version is no longer vulnerable.

Ask this paper

Key points
01

Benchmark. 500 real vulnerabilities from 290 repositories across six package ecosystems and 147 CWE categories, each with snapshots before and after the fix. The agent gets only the CWE description and read-only terminal access.

02

Scale of evaluation. 27 language models and four static-analysis tools are evaluated under a common agent interface.

03

Results. The strongest system reaches 0.229 File F1, and 38.4% of tasks get no correct localization from any model.

04

False reports after the fix. Systems that localize well can still report unsupported locations on patched repositories.

Abstract

Language-model agents increasingly operate over complete software repositories, yet cybersecurity evaluations primarily measure whether they can detect, reproduce, or repair vulnerabilities rather than whether they can locate the relevant code. We study vulnerability localization: given a weakness class and an unfamiliar repository, identify the implementation files associated with that weakness. We introduce the Vulnerability Localization Benchmark (VLoc Bench), comprising 500 real world vulnerabilities from 290 repositories across six package ecosystems and 147 CWE categories. Each task pairs repository snapshots immediately before and after a security fix. On the vulnerable snapshot, an agent receives only the CWE description and read-only terminal access and must return the affected files; on the patched snapshot, it must determine that the recorded vulnerability is no longer present. We evaluate 27 language models and four static-analysis tools under a common agent interface. Repository-scale vulnerability localization remains difficult: the strongest system achieves 0.229 File F1, and 38.4% of tasks receive no correct localization from any evaluated model. We further find that stronger localization does not imply reliable behavior after remediation: systems that identify vulnerable files effectively can still report unsupported locations on patched repositories. These results establish vulnerability localization as a distinct repository-scale capability and provide a setting for studying both how security agents search for vulnerable code and when they should refrain from reporting it.

Every Monday
Get next week’s papers.
Subscribe on Substack