Snyk Snyk VulnBench JS 1.0 Reveals Inconsistencies in LLM Security Findings
Article Content
- •LLM security findings show significant variability, with 50% appearing only once in scans.
- •Reference-matched findings were stable, indicating a need for combining LLMs with traditional SAST tools.
- •The highest-recall LLM configuration found only 81% of Snyk Code reference vulnerabilities.
Snyk conducted 300 vulnerability scans to evaluate the repeatability of LLM security reviews on identical code and prompts. The results showed that while reference-matched findings were stable, extra-model reports varied significantly. Out of 161 unique unmatched findings, 80 appeared only once across five identical scans, while 134 of 158 matched findings were consistent across all repetitions. The benchmark highlighted that LLMs can identify high-signal exploit shapes but also produce inconsistent results. The highest-recall LLM configuration detected only 81% of Snyk Code reference vulnerabilities, with nearly 50% of LLM-only reports appearing in just one of five scans. This raises questions about the reliability of LLMs in security assessments compared to traditional deterministic SAST tools. The benchmark was designed to measure model behavior under controlled conditions using JavaScript and Express applications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
BreachLock 2026 Report Reveals Critical Vulnerabilities in AI and Mobile Apps The BreachLock 2026 Penetration Testing Intelligence Report analyzes 531,770 security findings from 4,970 penetration tests across over 60 industries. It identifies that hardcoded credentials in iOS applications accounted for 97% of all critical mobile findings. Insecure design and business logic flaws (OWASP A04)…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…