arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CVE数据库宣称智能合约存在漏洞:附带标签与源代码位置

Smart Contracts Claimed Vulnerable by the CVE Database, with Labels and Source Locations

Monika di Angelo, Gernot Salzer

arXiv 2609.01186首次发表:更新:

发表机构

Institute of Computer Engineering, Informatics, TU Wien; Division of Theoretical Computer ScienceKTH Royal Institute of Technology; Institute of Logic and Computation, Informatics, TU Wien(TU Wien 计算机工程与信息学研究所; KTH皇家理工学院理论计算机科学系; TU Wien 逻辑与计算信息学研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文构建了含491条记录的CVE-Smart-Contracts数据集,针对以太坊智能合约漏洞,经自动化处理及15%人工审核,可支撑代码分析与修复技术评估。

AI 中文摘要

通用漏洞披露(Common Vulnerabilities and Exposures,CVE)数据库收录了硬件和软件中的漏洞声明,其中包括区块链程序即智能合约相关的漏洞。本文提出CVE-Smart-Contracts,这是一个截至2026年7月的、经过整理的CVE记录数据集,涉及以太坊智能合约。该数据集包含易受攻击的制品(源代码和运行时字节码)、三种分类体系下的标签以及函数级别的位置。CVE记录的检索、额外证据的收集、记录与制品对应关系的验证、标签分配以及漏洞定位均实现了自动化,仅15%的工作需人工分析。该数据集未验证原始漏洞声明,仅将少数明显错误的记录标记为“refuted”(被驳斥)。为确保可复现性,所有外部输入均被保留,因此重新运行流程将产生相同的输出。该数据集包含491条与已部署合约关联的记录、26条涉及项目(主要是库)的记录、45条无验证制品的记录以及6条被驳斥的声明记录。该数据集支持实证安全研究,尤其是代码分析和修复技术的评估。

英文摘要

The Common Vulnerabilities and Exposures (CVE) database catalogs vulnerability claims in hard- and software, among them those pertaining to blockchain programs a.k.a. smart contracts. We present CVE-Smart-Contracts, a curated dataset of CVE records up to July 2026 referring to Ethereum smart contracts. The dataset contains the vulnerable artifacts (source code and runtime bytecode), labels according to three taxonomies, and function-level locations. The retrieval of CVE records, collection of additional evidence, validation of the correspondence between records and artifacts, label assignment, and vulnerability localization are automated, leaving 15% to manual analysis. The dataset does not validate the original vulnerability claims, but marks a few records obviously wrong as `refuted'. For the sake of reproducibility, all external inputs are retained, so that rerunning the pipelines results in the same outputs. The dataset comprises 491 records linked to deployed contracts, 26 referring to projects (mostly libraries), 45 without validated artifacts, and six records with refuted claims. The dataset supports empirical security research, in particular the evaluation of code analysis and repair techniques.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑