LLM03:2025: Supply Chain
Compromised models, datasets, embeddings, or third-party fine-tunes pulled from public hubs (HuggingFace, ModelScope) carrying backdoors or poisoned weights.
How it's found
Detected by inspecting model, dataset, and dependency provenance for unverified sources and missing integrity checks.
Standards mapping
How TurboPentest tests for this (white-box)
Reliance on an Insufficiently Trustworthy Component is partly caught by white-box software composition analysis when you connect a GitHub repo: Dep Scanner (SCA) flags dependencies that carry known vulnerabilities or are outdated. Assessing the full trustworthiness of the supply chain, including build systems and package provenance, benefits from a manual IntegSec engagement with deeper methodology.
Tools: Dep Scanner
Frequently asked questions
What is LLM03:2025 Supply Chain?
Compromised models, datasets, embeddings, or third-party fine-tunes pulled from public hubs (HuggingFace, ModelScope) carrying backdoors or poisoned weights.
How do you find Supply Chain?
Detected by inspecting model, dataset, and dependency provenance for unverified sources and missing integrity checks.
Which CWEs map to LLM03:2025?
LLM03:2025 maps to CWE-1357, CWE-829, CWE-494.
Does TurboPentest test for Supply Chain?
Reliance on an Insufficiently Trustworthy Component is partly caught by white-box software composition analysis when you connect a GitHub repo: Dep Scanner (SCA) flags dependencies that carry known vulnerabilities or are outdated. Assessing the full trustworthiness of the supply chain, including build systems and package provenance, benefits from a manual IntegSec engagement with deeper methodology.
Related OWASP categories
- OWASP Top 10 for LLM ApplicationsLLM01:2025: Prompt Injection
- OWASP Top 10 for LLM ApplicationsLLM02:2025: Sensitive Information Disclosure
- OWASP Top 10 for LLM ApplicationsLLM04:2025: Data and Model Poisoning
- OWASP Top 10 for LLM ApplicationsLLM05:2025: Improper Output Handling
- OWASP Top 10 for LLM ApplicationsLLM06:2025: Excessive Agency
- OWASP Top 10 for LLM ApplicationsLLM07:2025: System Prompt Leakage
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest