Framework hub · LLM01–LLM10

The OWASP LLM Top 10.

The defining security-risk catalog for LLM-powered applications. Maintained by the OWASP GenAI Security Project. Each risk below has a dedicated deep-dive page with definition, examples, controls, and Posture Check mapping.

10 risks · LLM01–LLM10 · maintained by OWASP
LLM01

Prompt Injection

An attacker manipulates an LLM through crafted inputs that override instructions, exfiltrate context, or trigger unintended actions.

Posture Check questions Q11–Q15 Read deep-dive
LLM02

Sensitive Information Disclosure

An LLM reveals sensitive data through output.

Posture Check questions Q6–Q10 Read deep-dive
LLM03

Supply Chain

Vulnerabilities or compromises in upstream training data, pre-trained models, third-party datasets, model marketplaces, or fine-tuning services that affect the security of the deployed system..

Posture Check questions Q26–Q30 Read deep-dive
LLM04

Data and Model Poisoning

An attacker injects malicious data into training, fine-tuning, or RAG-corpus content to alter model behavior in their favor — often subtly, often persistently..

Posture Check questions Q16–Q20 Read deep-dive
LLM05

Improper Output Handling

Downstream systems trust LLM output and execute it without validation, leading to traditional injection vulnerabilities (XSS, SQL injection, command execution) being introduced through LLM-generated payloads..

Posture Check questions Q11–Q15 plus Q21–Q25 Read deep-dive
LLM06

Excessive Agency

An LLM-based agent has more permissions, more tool access, or more autonomy than its task requires.

Posture Check questions Q21–Q25 Read deep-dive
LLM07

System Prompt Leakage

An attacker extracts the system prompt or other privileged context from an LLM.

Posture Check questions Q11–Q15 Read deep-dive
LLM08

Vector and Embedding Weaknesses

Risks specific to vector databases, embedding models, and RAG architectures.

Posture Check questions Q6–Q10 plus Q16–Q20 Read deep-dive
LLM09

Misinformation

An LLM generates incorrect or misleading content that the user trusts and acts on.

Posture Check questions Q16–Q20 Read deep-dive
LLM10

Unbounded Consumption

An LLM service is consumed in ways that drive cost, latency, or availability problems.

Posture Check questions Q21–Q25 Read deep-dive

How exposed are you to LLM01–LLM10?

The Posture Check evaluates 30 questions across six dimensions, with explicit mapping to OWASP LLM Top 10. Ten minutes, free, in-browser, no email required.

Take the AI Posture Check