logo

OWASP Top 10 for LLM Applications


Summary

The OWASP Top 10 for Large Language Model Applications highlights the most critical security risks in LLM applications, explaining their potential impact, ease of exploitation, and prevalence in real-world applications.


Definitions

DefinitionRequirements
OWASPLLM-LLM01:2025. Prompt Injection
OWASPLLM-LLM02:2025. Sensitive Information Disclosure
OWASPLLM-LLM03:2025. Supply Chain
OWASPLLM-LLM04:2025. Data and Model Poisoning
OWASPLLM-LLM05:2025. Improper Output Handling
OWASPLLM-LLM06:2025. Excessive Agency
OWASPLLM-LLM07:2025. System Prompt Leakage
OWASPLLM-LLM08:2025. Vector and Embedding Weaknesses
OWASPLLM-LLM09:2025. Misinformation
OWASPLLM-LLM10:2025. Unbounded Consumption

Last updated

2025/06/17