Version 2025November 18, 2024 OWASP PDF v4.2.0a 20241114-202703 LICENSE AND USAGE This document is licensed under Creative Commons, CC BY-SA 4.0. You are free to:Share — copy and redistribute the material in any medium or format for any purpose,even commercially.Adapt — remix, transform, and build upon the material for any purpose,even commercially. The licensor cannot revoke these freedoms as long as you follow the license terms. Under the following terms: Attribution — You must give appropriate credit, provide a link to the license, and indicateif changes were made. You may do so in any reasonable manner, but not in any waythat suggests the licensor endorses you or your use.ShareAlike — If you remix, transform, or build upon the material, you must distributeyour contributions under the same license as the original.No additional restrictions — You may not apply legal terms or technological measuresthat legally restrict others from doing anything the license permits. Link to full license text: https://creativecommons.org/licenses/by-sa/4.0/legalcode The information provided in this document does not, and is not intended to constitutelegal advice. All information is for general informational purposes only.This document contains links to other third-party websites. Such links are only forconvenience and OWASP does not recommend or endorse the contents of the third-partysites. REVISION HISTORY 2023-08-01 Version 1.0 Release2023-10-16 Version 1.1 Release2024-11-18 Version 2025 Release Table of Contents What’s New in the 2025 Top 10. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .1Moving Forward. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .2 Description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .3Types of Prompt Injection Vulnerabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .3Prevention and Mitigation Strategies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .4Example Attack Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .5Reference Links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6Related Frameworks and Taxonomies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .6 LLM02:2025 Sensitive Information Disclosure. . . . . . . . . . . . . . . . . . . . . . . . . .7 Description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7Common Examples of Vulnerability. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .7Prevention and Mitigation Strategies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .8Example Attack Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9Reference Links . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9Related Frameworks and Taxonomies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9 LLM03:2025 Supply Chain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11 Description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11Common Examples of Risks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11Prevention and Mitigation Strategies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .12Sample Attack Scenarios . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .13Reference Links. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15Related Frameworks and Taxonomies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .15 Description. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .16Common Examples of Vulnerability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .16Prevention and Mitigation Strategies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17Example Attack Scenarios. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17Reference Links. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .18Related Frameworks and Taxonomies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .18 LLM05:2025 Improper Output Handling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19 Description. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19 Common Examples of Vulnerability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .19Prevention and Mitigation Strategies. . . . . . . . . . .