Supply chain risks arise when you are dependent on parts from others. If such a part is vulnerable, malicious or poorly maintained, this can have consequences for your own product.
This risk is not exclusive to open source, but open source often makes dependencies more visible.