LLM agent scaffolding systematically finds broken access control vulnerabilities in web apps
Duarte et al. present ABSENTIA, a security scaffolding that directs LLM agents to systematically audit web application backends for broken access control. The agents build a route–code graph and apply invariant falsification to infer intended authorization properties, reporting routes where they are not enforced. On a new benchmark of 30 real-world advisories (BAC-Bench), ABSENTIA recalls 19 vulnerabilities with 17 under strict credit; CodeQL and Semgrep recall none.