Search papers, labs, and topics across Lattice.
This paper analyzes 295 GitHub Security Advisories related to LLM-integrated open-source software to understand how well existing vulnerability disclosure frameworks capture model-mediated risks. By manually annotating a subset of advisories using the OWASP Top 10 for LLM Applications, the authors find that while code-level defects are well-represented by CWEs, architectural risks like Supply Chain, Excessive Agency, and Prompt Injection are underrepresented. The study concludes that a combined CWE and OWASP perspective is needed for a comprehensive understanding of vulnerabilities in LLM-integrated systems.
Current vulnerability disclosures miss the biggest risks in LLM-integrated systems: architectural flaws like supply chain vulnerabilities and excessive agency, not just code-level bugs.
Large language models (LLMs) are increasingly embedded in open-source software (OSS) ecosystems, creating complex interactions among natural language prompts, probabilistic model outputs, and execution-capable components. However, it remains unclear whether traditional vulnerability disclosure frameworks adequately capture these model-mediated risks. To investigate this, we analyze 295 GitHub Security Advisories published between January 2025 and January 2026 that reference LLM-related components, and we manually annotate a sample of 100 advisories using the OWASP Top 10 for LLM Applications 2025. We find no evidence of new implementation-level weakness classes specific to LLM systems. Most advisories map to established CWEs, particularly injection and deserialization weaknesses. At the same time, the OWASP-based analysis reveals recurring architectural risk patterns, especially Supply Chain, Excessive Agency, and Prompt Injection, which often co-occur across multiple stages of execution. These results suggest that existing advisory metadata captures code-level defects but underrepresents model-mediated exposure. We conclude that combining the CWE and OWASP perspectives provides a more complete and necessary view of vulnerabilities in LLM-integrated systems.