OWASP Top 10 for LLM applications (2025)

The OWASP Top 10 for LLM Applications 2025 lists ten risks: prompt injection (LLM01), sensitive information disclosure (LLM02), supply chain (LLM03), data and model poisoning (LLM04), improper output handling (LLM05), excessive agency (LLM06), system prompt leakage (LLM07), vector and embedding weaknesses (LLM08), misinformation (LLM09) and unbounded consumption (LLM10). A proxy can help with parts of some, and none with others.

The ten risks at a glance

This is the 2025 edition, published by the OWASP GenAI Security Project at genai.owasp.org/llm-top-10, which is the source for the names and order below. The one-line meanings are my own summaries. Read OWASP's pages for the authoritative text, which I link under each risk.

OWASP Top 10 for LLM Applications 2025
IDRiskIn short
LLM01Prompt InjectionCrafted input, typed by a user or hidden in content the model reads, changes the model's behaviour in ways the developer did not intend.
LLM02Sensitive Information DisclosureThe model or application reveals personal data, confidential business information or credentials through its output.
LLM03Supply ChainThird-party models, datasets, adapters, libraries and platforms can be vulnerable or tampered with.
LLM04Data and Model PoisoningPre-training, fine-tuning or embedding data is manipulated to introduce backdoors, bias or vulnerabilities.
LLM05Improper Output HandlingModel output is passed to other components without enough validation or sanitisation, enabling issues such as cross-site scripting or injection into back-end systems.
LLM06Excessive AgencyA model-based system is given more functionality, permissions or autonomy than it needs, so a manipulated model can take damaging actions.
LLM07System Prompt LeakageSystem prompts can contain sensitive information, and attackers can extract them. OWASP stresses that security controls should not depend on keeping the prompt secret.
LLM08Vector and Embedding WeaknessesWeaknesses in how vectors and embeddings are generated, stored and retrieved in RAG systems can expose data or let attackers inject content.
LLM09MisinformationThe model produces false or misleading content that appears credible, and users or systems over-rely on it.
LLM10Unbounded ConsumptionExcessive or uncontrolled inference leads to denial of service, runaway cost or model extraction.

LLM01: Prompt Injection

Crafted input, typed by a user or hidden in content the model reads, changes the model's behaviour in ways the developer did not intend. (OWASP page)

Example: Hidden text on a web page tells a summarising agent to reveal the conversation.

Typical controls: Constrain model behaviour, validate output formats, filter inputs and outputs, enforce least privilege, require human approval for high-risk actions, segregate external content and run adversarial tests.

What a proxy like AiDren covers: partly. Judge-model screening of every request, including multi-turn, with fail-closed behaviour, plus custom policy rules. It is a probabilistic classifier and will not catch every novel attack. Privilege design and approvals remain yours. See prompt injection protection.

LLM02: Sensitive Information Disclosure

The model or application reveals personal data, confidential business information or credentials through its output. (OWASP page)

Example: A support bot echoes a customer's card number from earlier in the context, or an API key pasted into a prompt appears in a reply.

Typical controls: Sanitise and minimise data that reaches the model, apply access controls, scan outputs, and keep secrets out of prompts.

What a proxy like AiDren covers: partly. Output scanning for emails, card numbers, IBANs, phone numbers, API keys and private keys, with redact or block, per key. It does not know your own secrets unless you add custom term or regex rules, and it does not fix what a model memorised in training. See output scanning.

LLM03: Supply Chain

Third-party models, datasets, adapters, libraries and platforms can be vulnerable or tampered with. (OWASP page)

Example: A downloaded model checkpoint is a pickle file that runs code when loaded.

Typical controls: Vet and pin sources, verify integrity, prefer safe formats such as safetensors, scan files, and keep an inventory of components.

What a proxy like AiDren covers: partly. Model-file scanning for pickle, safetensors, GGUF, ONNX, joblib and Keras files fetched from Hugging Face Hub or GitHub through the proxy. It does not assess your Python dependencies, datasets, third-party plugins or the provenance of a model's behaviour. See model-file scanning.

LLM04: Data and Model Poisoning

Pre-training, fine-tuning or embedding data is manipulated to introduce backdoors, bias or vulnerabilities. (OWASP page)

Example: Poisoned examples in a fine-tuning set make the model misbehave on a trigger phrase.

Typical controls: Track data provenance, validate and filter training data, test models for backdoors and monitor behaviour.

What a proxy like AiDren covers: not covered. Nothing directly. A proxy sees runtime traffic, not your training pipeline. Model-file scanning can flag malicious code in a file, but it does not detect poisoned weights or tainted training data.

LLM05: Improper Output Handling

Model output is passed to other components without enough validation or sanitisation, enabling issues such as cross-site scripting or injection into back-end systems. (OWASP page)

Example: A model's reply containing a script tag is rendered into a web page unescaped.

Typical controls: Treat output as untrusted, validate against schemas, encode for the destination context and use parameterised queries.

What a proxy like AiDren covers: partly. Response scanning and custom regex or term rules can block or redact known-bad patterns. AiDren does not encode or sanitise output for your downstream context. That has to happen in your application.

LLM06: Excessive Agency

A model-based system is given more functionality, permissions or autonomy than it needs, so a manipulated model can take damaging actions. (OWASP page)

Example: An email agent that can send and delete messages is tricked into forwarding a mailbox.

Typical controls: Minimise tools and permissions, scope credentials per user, require human approval and execute actions in the user's context.

What a proxy like AiDren covers: partly. Visibility only: the egress worker-agent reports unexpected outbound connections and never blocks them, and screening may catch some hijack attempts. Permissions, tool scope and approvals are your design. See egress monitoring.

LLM07: System Prompt Leakage

System prompts can contain sensitive information, and attackers can extract them. OWASP stresses that security controls should not depend on keeping the prompt secret. (OWASP page)

Example: A user asks the bot to repeat its hidden instructions verbatim and gets credentials or business rules.

Typical controls: Keep secrets out of prompts, enforce controls outside the model and monitor for extraction attempts.

What a proxy like AiDren covers: partly. A system-prompt-leak detector on responses, and screening for extraction attempts. It reduces exposure but cannot make a prompt secret, so assume yours will eventually be read.

LLM08: Vector and Embedding Weaknesses

Weaknesses in how vectors and embeddings are generated, stored and retrieved in RAG systems can expose data or let attackers inject content. (OWASP page)

Example: A shared vector store returns another tenant's documents because access control was applied after retrieval.

Typical controls: Apply permission-aware retrieval, validate and monitor what enters the store, and segregate tenants' data.

What a proxy like AiDren covers: not covered. Not covered. AiDren does not sit between your application and its vector database. It can screen retrieved text only if that text is sent to the model through the proxy.

LLM09: Misinformation

The model produces false or misleading content that appears credible, and users or systems over-rely on it. (OWASP page)

Example: A model invents a plausible but non-existent legal citation or software package.

Typical controls: Use retrieval grounding, human review, verification of citations and clear communication of limits.

What a proxy like AiDren covers: not covered. Not covered. A security proxy does not judge factual accuracy, and I would not claim otherwise.

LLM10: Unbounded Consumption

Excessive or uncontrolled inference leads to denial of service, runaway cost or model extraction. (OWASP page)

Example: An attacker sends enormous prompts in a loop and runs up your provider bill.

Typical controls: Rate limits, input size caps, quotas and budget alerts at the provider and application level.

What a proxy like AiDren covers: partly. Limited. A threshold rule can cap message length and every request is logged, and AiDren's own fair-use allowance and burst limits protect AiDren's service. It is not a per-user cost-control system, so set budgets and rate limits at your provider and in your app.

What a proxy can and cannot cover

Here is the honest summary for AiDren, a self-serve LLM security proxy. I have not marked any risk as fully covered, because no runtime filter fully removes any of them. “Partly” means a real control exists that reduces the risk but leaves a gap you must close elsewhere. “Not covered” means a proxy sits in the wrong place to help.

Which OWASP LLM risks AiDren covers
RiskAiDren coverageWhat that means
LLM01 Prompt InjectionPartlyScreens inputs; cannot catch every novel attack
LLM02 Sensitive Information DisclosurePartlyScans responses for common patterns; custom rules for your own data
LLM03 Supply ChainPartlyScans model files from Hugging Face and GitHub; not dependencies or datasets
LLM04 Data and Model PoisoningNot coveredDoes not see training data or detect poisoned weights
LLM05 Improper Output HandlingPartlyPattern rules on responses; you must encode and validate output
LLM06 Excessive AgencyPartlyReports unexpected connections; permissions and approvals are yours
LLM07 System Prompt LeakagePartlyDetects prompt echoes in responses; cannot make a prompt secret
LLM08 Vector and Embedding WeaknessesNot coveredNo visibility into your vector store or retrieval
LLM09 MisinformationNot coveredDoes not judge factual accuracy
LLM10 Unbounded ConsumptionPartlyMessage-length cap and logging only; budgets and rate limits are yours

Seven of the ten get partial help, and three (data and model poisoning, vector and embedding weaknesses, misinformation) get none. That pattern is typical for any runtime layer: it is strongest where the risk shows up in the traffic to and from the model. The rest needs design work, data governance and review.

To work through the highest-ranked risk in practice, use the prevention checklist, look at concrete attack examples, and run the free attack test. For the product behind the coverage above, see prompt injection protection, output scanning, model-file scanning and egress monitoring, or read what an LLM firewall is and is not.

Frequently asked questions

What are the OWASP Top 10 for LLM applications?

It is a ranked list from the OWASP GenAI Security Project of the most critical risks in LLM-based applications. The 2025 edition is: LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM03 Supply Chain, LLM04 Data and Model Poisoning, LLM05 Improper Output Handling, LLM06 Excessive Agency, LLM07 System Prompt Leakage, LLM08 Vector and Embedding Weaknesses, LLM09 Misinformation and LLM10 Unbounded Consumption.

What is the number one risk on the OWASP LLM Top 10?

Prompt injection, listed as LLM01:2025. It covers both direct injection, where a user's input alters the model's behaviour, and indirect injection, where instructions hide in content the model processes.

Can one tool cover the whole OWASP LLM Top 10?

No. Several risks, such as data poisoning, vector and embedding weaknesses and misinformation, sit in your training pipeline, retrieval design and review processes, not in the request path. A proxy can address parts of prompt injection, information disclosure, supply chain and system prompt leakage.

Is the 2025 list the latest version?

As of 1 October 2026 the 2025 list is the edition published on the OWASP GenAI Security Project site. Check genai.owasp.org for updates.

How does the AiDren attack test relate to OWASP?

The full attack test runs about 20 prompt-injection and jailbreak attacks that are tagged to OWASP categories, and shows what got through with protection off versus on. It tests your system prompt against attacks, so it speaks mainly to LLM01 and LLM07, not the whole list.

Test your own prompt, free

Paste a system prompt into the free 6-attack demo and see which attacks get through. No signup. The full ~20-attack test is in the 14-day trial (no card). Prices are on the pricing page.