JAVA.SV.LLM.TOOL.PRIV

Privileged LLM tool action without an authorization check

The JAVA.SV.LLM.TOOL.PRIV checker identifies privileged or destructive LLM tool actions that do not enforce an authorization check.

Vulnerability and risk

An LLM tool that can perform a privileged or destructive action without an authorization check can let the model exceed the permissions intended for the current user.

Mitigation and prevention

Require an authorization check before an LLM can invoke a privileged or destructive tool.

Vulnerable code example

Copy
import dev.langchain4j.agent.tool.Tool;

public class AccountTools {
    private final UserAdminService userAdminService;

    public AccountTools(UserAdminService userAdminService) {
        this.userAdminService = userAdminService;
    }

    @Tool("Delete a user account")
    public void deleteUser(String accountId) {
        userAdminService.deleteAccount(accountId); // destructive action with no authorization check
    }
}

Fixed code example

Copy
import dev.langchain4j.agent.tool.Tool;

public class AccountTools {
    private final AuthorizationService authorizationService;
    private final UserAdminService userAdminService;

    public AccountTools(AuthorizationService authorizationService, UserAdminService userAdminService) {
        this.authorizationService = authorizationService;
        this.userAdminService = userAdminService;
    }

    @Tool("Delete a user account")
    public void deleteUser(String accountId, UserPrincipal principal) {
        authorizationService.requirePermission(principal, "accounts:delete");
        userAdminService.deleteAccount(accountId);
    }
}

Security training

Application security training materials provided by Secure Code Warrior.