# Securing the Open Source AI Ecosystem with Pranshu Raghav

DevFeed: [Securing the Open Source AI Ecosystem with Pranshu Raghav](<https://devfeed.tech/articles/securing-the-open-source-ai-ecosystem-with-pranshu-raghav-64965.md>)

Original publisher: [Read original article](<https://hackernoon.com/securing-the-open-source-ai-ecosystem-with-pranshu-raghav?source=rss>)

Author: Jon Stojan Journalist

Published: 2026-10-05T09:00:06Z

Content type: article

Language: en

Sources: [HackerNoon](<https://devfeed.tech/sources/hackernoon.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [AI software supply chain security](<https://devfeed.tech/topics/ai-software-supply-chain-security.md>)

Tags: [access-controls](<https://devfeed.tech/tags/access-controls.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent-security-risks](<https://devfeed.tech/tags/ai-agent-security-risks.md>), [ai-framework-security](<https://devfeed.tech/tags/ai-framework-security.md>), [ai-security-architecture](<https://devfeed.tech/tags/ai-security-architecture.md>), [ai-supply-chain-attacks](<https://devfeed.tech/tags/ai-supply-chain-attacks.md>), [ai-vulnerability-disclosure](<https://devfeed.tech/tags/ai-vulnerability-disclosure.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [good-company](<https://devfeed.tech/tags/good-company.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [open-source-ai-security](<https://devfeed.tech/tags/open-source-ai-security.md>), [open-source-ai-vulnerabilities](<https://devfeed.tech/tags/open-source-ai-vulnerabilities.md>), [ssrf](<https://devfeed.tech/tags/ssrf.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

## AI overview

Open-source AI frameworks are entering enterprise infrastructure, bringing supply chain and application security risks. Pranshu Raghav discusses issues including agent goal hijacking, SSRF, IDOR, weak access controls, and vulnerabilities that can spread through integrations. The article also argues for earlier threat modeling, asset tracking, coordinated disclosure, and sustained support for open-source maintainers.

## Source excerpt

Open-source AI frameworks are becoming part of enterprise infrastructure. Learn how supply chain flaws, SSRF, IDOR, & weak access controls expand the AI attack.