# Inclusion of Functionality from Untrusted Control Sphere (CWE-829) The product imports, requires, or includes executable functionality from a source that is outside of the intended control sphere. **Stack:** Go - Prevalence: Alta Frequentemente explorada - Impact: Alto 3 regras de severidade alta - Prevention: Documentada 4 exemplos de correção **OWASP:** Vulnerable and Outdated Components (A06:2021-Vulnerable and Outdated Components) - #6 ## Description When software includes functionality from untrusted sources (such as third-party scripts, external modules, or code from untrusted URLs), attackers can inject malicious code that will be executed with the same privileges as the application. ## Prevention Estratégias de prevenção para Inclusion of Untrusted Functionality baseadas em 1 regras de detecção do Shoulder. ### Go Use an allowlist for permitted models, verify integrity with checksums, and load models over HTTPS only ## Warning Signs - [HIGH] Potential supply chain vulnerability: ... - [HIGH] supply chain vulnerabilities in AI/LLM implementations such as untrusted model sources or dynamic mo ## Consequences - Executar código não autorizado - Ler dados da aplicação - Modificar dados da aplicação ## Mitigations - Inclua apenas código de fontes confiáveis e verificadas - Use Subresource Integrity (SRI) para scripts externos - Implemente Content Security Policy (CSP) para restringir fontes de código executável ## Detection - Total rules: 4 - Languages: go, javascript, typescript, yaml, python ## Rules by Language ### Go (1 rules) - **LLM Supply Chain Vulnerabilities** [HIGH]: Detects supply chain vulnerabilities in AI/LLM implementations such as untrusted model sources or dynamic model loading. - Remediation: Use an allowlist for permitted models and verify integrity with checksums. ```go if _, ok := allowedModels[modelID]; !ok { return errors.New("model not in allowlist") } ``` Learn more: https://shoulder.dev/learn/go/cwe-829/llm-supply-chain