OWASP Top 10 for LLM Applications 2025 OWASPLLM-4: Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)
Address OWASP LLM03:2025 Supply Chain + LLM08:2025 Vector and Embedding Weaknesses. Supply Chain risk arises from third-party models + datasets + libraries + frameworks + plugins + tools + agent capabilities + including model poisoning + backdoors + malicious packages + license issues. Vector and Embedding Weaknesses arise from vector database + embedding model usage including unauthorised access to embeddings + embedding inversion attacks + retrieval poisoning + cross-context leakage in shared vector stores. Mitigations include (a) maintain inventory of third-party models + datasets + libraries + tools with provenance verification + (b) scan for vulnerabilities + license issues + malicious content + (c) implement model signing + integrity verification + (d) implement access control + isolation for vector databases + (e) implement embedding access control + prevent unauthorised retrieval + (f) protect against retrieval poisoning via source vetting + (g) implement isolation in multi-tenant vector stores.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 67 controls across 42 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.