I am Xiang Mei (n132), a Ph.D. student at Arizona State University, working with Dr. Yan Shoshitaishvili (advisor), Dr. Ruoyu (Fish) Wang, Dr. Adam Doupé, and Dr. Tiffany Bao in the SEFCOM lab. My research primarily revolves around automated binary analysis, vulnerability discovery, and exploitation. Prior to my doctoral studies, I earned my Master’s degree from NYU in 2023, where I conducted research (ARVO) with Dr. Brendan Dolan-Gavitt.

Since my sophomore year, I have been actively engaged in Capture The Flag (CTF) competitions. I compete as part of Shellphish and r3kapig teams under the handle n132, specializing in binary exploitation (PWN). Recently, I became the tenth person to solve all challenges on Pwnable.tw, a journey that spanned seven years and built my exploitation skills. Moreover, I have been a DEF CON CTF finalist between 2021-2026. During my master’s study at NYU, I served as the Lab Manager for NYU Osiris Lab, organizing CSAW-CTFs in 2021 and 2022. I also participated in bug bounty programs to tackle real-world security challenges, such as the Linux kernel in Google’s kernelCTF, and WYZE-V3 camera at PWN2OWN Toronto.

I like open-source, contributing to major projects like the Linux kernel and oss-fuzz. I share various exploitation tools and techniques I develop on my GitHub, including Libc-GOT-Hijacking, Dec-Safe-Linking, BeapOverflow, and more.

News

Aug 2026 Finished Internship at Microsoft (MSR, MDASH)
Jul 2026 ARVO got Distinguished Paper Award on Euro S&P
Mar 2026 KernelCTF: Exploited Linux kernel v6.12.74
Mar 2026 Our paper, ARVO, got accepted in Euro S&P 2026
Aug 2025 Shellphish got 5th in AIxCC Final Event
Jun 2025 KernelCTF: Exploited Linux kernel v6.6.95

Links

Papers

ARVO: Atlas of Reproducible Vulnerabilities for Open-Source Software (Distinguished Paper Award)
Xiang Mei, Jordi Del Castillo, Pulkit Singh Singaria, Haoran Xi, Abdelouahab Benchikh, Tiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, Adam Doupé, Hammond Pearce, Brendan Dolan-Gavitt
2026 11th IEEE European Symposium on Security and Privacy (EuroS&P)

Achieving reproducibility, quantity, and diversity in vulnerability datasets has long been viewed as an inherent three-way trade-off, where improving one dimension often comes at the cost of the others. In practice, reproducibility has been the dimension most often neglected. This has limited what can be automatically extracted from historical bug datasets, and has reduced their utility for downstream security research. In this work, we propose a method to produce a new security dataset which ensures reproducibility for diverse vulnerabilities at scale by identifying the key obstacles to large-scale bug reproduction and addressing them with general solutions. Using this method, we introduce full reproducibility to the largest open source software vulnerability dataset (OSS-Fuzz) and construct the ARVO dataset (an Atlas of Reproducible Vulnerabilities in Open-source software). ARVO is a large-scale dataset consisting of over 6,100 real-world vulnerabilities across 311 projects. Focusing on reproducibility, ARVO differs from existing datasets by providing each vulnerability in a form that can be consistently rebuilt, triggered, and analyzed across versions. Reproducibility also enables automatic identification of the corresponding patch for each vulnerability and supports direct interaction with vulnerabilities after code changes, capabilities that existing large-scale datasets do not provide. In our evaluation, ARVO successfully reproduces 81% of vulnerabilities and achieves 89.4% accuracy on the located patches. We also discuss ARVO’s influence on both upstream practices and downstream security research.

Community Contributions

Discovered / Patched CVEs
CVE-2025-38477 CVE-2025-40083 CVE-2025-68325 CVE-2026-22976 CVE-2026-22977 CVE-2026-23276 CVE-2026-23277 CVE-2026-23396 CVE-2026-23397 CVE-2026-23398 CVE-2026-23439 CVE-2026-31419 CVE-2026-31420 CVE-2026-31421 CVE-2026-31422 CVE-2026-31423 CVE-2026-31424 CVE-2026-31425 CVE-2026-31426 CVE-2026-31427 CVE-2026-31428 CVE-2026-31546 CVE-2026-43085 CVE-2026-43086 CVE-2026-45837 CVE-2026-45838 CVE-2026-45839 CVE-2026-45840 CVE-2026-45841 CVE-2026-45842 CVE-2026-45843 CVE-2026-45844 CVE-2026-45845 CVE-2026-45846 CVE-2026-46320 CVE-2026-46321 CVE-2026-46322 CVE-2026-52937 CVE-2026-52938 CVE-2026-52939 CVE-2026-52940 CVE-2026-52941 CVE-2026-52942 CVE-2026-53257 CVE-2026-53349 CVE-2026-63858 CVE-2026-64048 CVE-2026-64187 CVE-2026-64188 CVE-2026-64189 CVE-2026-64190 CVE-2026-64191 CVE-2026-64411 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64575 CVE-2026-64576 CVE-2026-64577 CVE-2026-64578 CVE-2026-64579 CVE-2026-64580 CVE-2026-64581 CVE-2026-68159 CVE-2026-68323 CVE-2026-72250 CVE-2026-72389 CVE-2026-72407 CVE-2026-72408 CVE-2026-74561 CVE-2026-74562 CVE-2026-74563 CVE-2026-74569 CVE-2026-74579 CVE-2026-74613 CVE-2026-74614 CVE-2026-74726