LLM03 · OWASP LLM Top 10

Supply Chain (LLM03)

Vulnerabilities or compromises in upstream training data, pre-trained models, third-party datasets, model marketplaces, or fine-tuning services that affect the security of the deployed system.

Rank
LLM03 of 10
In the check
Cited by 2 of the 16 questions
LLM01
Prompt Injection
LLM02
Sensitive Information Disclosure
LLM03
Supply Chain
LLM04
Data and Model Poisoning
LLM05
Improper Output Handling
LLM06
Excessive Agency
LLM07
System Prompt Leakage
LLM08
Vector and Embedding Weaknesses
LLM09
Misinformation
LLM10
Unbounded Consumption
Figure 1. The OWASP LLM Top 10, with LLM03 marked.
In practice

What it looks like in practice

Three shapes this risk takes in real deployments.

Example 1

A model downloaded from a hub contains a backdoor activated by a specific trigger phrase.

Example 2

A training dataset includes poisoned samples that cause the model to misbehave on specific topics.

Example 3

A vendor's fine-tuning service leaks the customer's training data.

Controls

Controls that close it

These count toward the Vendor and Model dimensions of the check.

Model provenance tracking

Vendor security due diligence

Model fingerprinting on receipt

Reproducible training where applicable

Continuous vendor monitoring

Posture Check

Where the check cites it

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint.

Question the check may askDimensionCitation
Do your AI vendor contracts cover data handling, breach notification, and audit rights? Vendor OWASP LLM03
Do you track which model versions are in use and have a way to retire one? Model OWASP LLM03, NIST AI RMF MEASURE-2.7
Ready when you are

Score yourself against this framework.

Five questions, each citing its source. You get your stage, your place on the chart and the one move that matters next.

  • A few minutes for most people
  • Free, from CWS
  • Your stage, the chart and the next move, by email or live with an engineer