Abstract
Large language models (LLMs) are increasingly embedded in open-source software (OSS) ecosystems, creating complex interactions among natural language prompts, probabilistic model outputs, and execution-capable components. However, it remains unclear whether traditional vulnerability disclosure frameworks adequately capture these model-mediated risks. To investigate this, we analyze 295 GitHub Security Advisories published between January 2025 and January 2026 that reference LLM-related components, and we manually annotate a sample of 100 advisories using the OWASP Top 10 for LLM Applications 2025.We find no evidence of new implementation-level weakness classes specific to LLM systems. Most advisories map to established CWEs, particularly injection and deserialization weaknesses. At the same time, the OWASP-based analysis reveals recurring architectural risk patterns, especially Supply Chain, Excessive Agency, and Prompt Injection, which often co-occur across multiple stages of execution. These results suggest that existing advisory metadata captures code-level defects but underrepresents model-mediated exposure. We conclude that combining the CWE and OWASP perspectives provides a more complete and necessary view of vulnerabilities in LLM-integrated systems.
Recommended Citation
F. T. Shifat et al., "LLM-Enabled Open-Source Systems In The Wild: An Empirical Study Of Vulnerabilities In GitHub Security Advisories," Fse Companion 2026 Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering, pp. 1565 - 1572, Association for Computing Machinery, Jul 2026.
The definitive version is available at https://doi.org/10.1145/3803437.3805532
Department(s)
Computer Science
Publication Status
Open Access
Keywords and Phrases
common weakness enumeration; GitHub security advisories; large language models; open source software; OWASP
Document Type
Article - Conference proceedings
Document Version
Citation
File Type
text
Language(s)
English
Rights
© 2026 The Author(s), All rights reserved.
Creative Commons Licensing

This work is licensed under a Creative Commons Attribution 4.0 License.
Publication Date
17 Jul 2026
