Framework hub · LLM01 to LLM10

The OWASP LLM Top 10.

The defining security-risk catalog for LLM-powered applications. Maintained by the OWASP GenAI Security Project. Each risk below has a dedicated deep-dive page with definition, examples, controls, and Posture Check mapping.

10 risks · LLM01 to LLM10 · maintained by OWASP
LLM01

Prompt Injection

An attacker manipulates an LLM through crafted inputs that override instructions, exfiltrate context, or trigger unintended actions.

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM02

Sensitive Information Disclosure

An LLM reveals sensitive data through output.

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM03

Supply Chain

Vulnerabilities or compromises in upstream training data, pre-trained models, third-party datasets, model marketplaces, or fine-tuning services that affect the security of the deployed system..

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM04

Data and Model Poisoning

An attacker injects malicious data into training, fine-tuning, or RAG-corpus content to alter model behavior in their favor, often subtly and often persistently..

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM05

Improper Output Handling

Downstream systems trust LLM output and execute it without validation, leading to traditional injection vulnerabilities (XSS, SQL injection, command execution) being introduced through LLM-generated payloads..

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM06

Excessive Agency

An LLM-based agent has more permissions, more tool access, or more autonomy than its task requires.

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM07

System Prompt Leakage

An attacker extracts the system prompt or other privileged context from an LLM.

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM08

Vector and Embedding Weaknesses

Risks specific to vector databases, embedding models, and RAG architectures.

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM09

Misinformation

An LLM generates incorrect or misleading content that the user trusts and acts on.

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
LLM10

Unbounded Consumption

An LLM service is consumed in ways that drive cost, latency, or availability problems.

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint Read deep-dive
Ready when you are

How exposed are you to LLM01 to LLM10?

The Posture Check asks up to five questions drawn from six dimensions, with explicit mapping to OWASP LLM Top 10. Ten minutes, free, in-browser, no email required.

Take the AI Posture Check