Tor is a well-designed and robust anonymity tool, and successfully attacking it is difficult. The NSA attacks we found individually target Tor users by exploiting vulnerabilities in their Firefox browsers, and not the Tor application directly.
This, too, is difficult. Tor users often turn off vulnerable services like scripts and Flash when using Tor, making it difficult to target those services. Even so, the NSA uses a series of native Firefox vulnerabilities to attack users of the Tor browser bundle.
Code:
http://www.theguardian.com/world/2013/oct/04/tor-attacks-nsa-users-online-anonymity
My comment: Actually, I don’t think NSA needs any vulnerabilities to track down IPs. There are standard methods of analyzing traffic at each node and matching outgoing to incoming IP.