2025ReviewedOpen access
OWASP Top 10 for Large Language Model Applications
Steve Wilson, OWASP LLM AI Security Team
OWASP Foundation
Abstract
The definitive OWASP guide identifying the top 10 most critical security risks in LLM applications, with descriptions, examples, and mitigation strategies.
Categories
#OWASP#top-10#standard#reference
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM02Sensitive Information Disclosure
- LLM03Supply Chain
- LLM04Data and Model Poisoning
- LLM05Improper Output Handling
- LLM06Excessive Agency
- LLM07System Prompt Leakage
- LLM08Vector and Embedding Weaknesses
- LLM09Misinformation
- LLM10Unbounded Consumption
Cite
@techreport{wilson2025owasp,
title = {{OWASP Top 10 for Large Language Model Applications}},
author = {Steve Wilson and {OWASP LLM AI Security Team}},
year = {2025},
institution = {OWASP Foundation},
url = {https://owasp.org/www-project-top-10-for-large-language-model-applications/}
}