The OWASP Top 10 For LLM Applications: The 2025 And 2026 Lists Explained
OWASP's Top 10 is a widely used checklist of risks in applications built on large language models. Here is what each entry means and what changed between the 2025 and 2026 editions.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
When a company adds a chatbot, a document assistant or a coding helper to its products, it inherits a new class of security problems. A large language model (LLM) reads text and produces text, and that simple fact opens doors that ordinary web applications do not have. Attackers can hide instructions in a document, coax out data the model was never meant to share, or run up a cloud bill by flooding the model with expensive requests.
The OWASP Top 10 for LLM Applications is a short, widely referenced list of these problems. OWASP is a non-profit community best known for its web application Top 10, and its GenAI Security Project maintains the LLM version. This article explains each entry in plain terms and shows how the list changed between the 2025 edition and the 2026 edition published in August 2026.1
What The List Is, And What It Is Not
The Top 10 is an awareness document. It names the risks that practitioners consider most serious for applications that use an LLM as one component, and for each one it gives examples, attack scenarios and mitigations. It is guidance, not a standard you can be certified against, and it does not by itself create any legal obligation. Its value is a shared vocabulary: when a developer, an auditor and a supplier all say “LLM01”, they mean the same thing.
Entries carry an ID and a year, such as LLM01:2025 or LLM01:2026. The number is the rank, so the same risk can have a different ID in each edition. That matters when you read older reports, because “LLM05” means Improper Output Handling in 2025 and Data and Model Poisoning in 2026.
The Ten Risks In Plain Language
The 2026 edition keeps nine of the 2025 risks and renames and broadens the tenth.23 In the 2026 order:
- Prompt Injection. Input that changes the model’s behaviour in ways the developer did not intend. It can come straight from a user, or hide in a web page, email, file, image or tool result the model reads.
- Sensitive Information Disclosure. The system exposes personal, regulated or confidential data. The 2026 text stresses that the leak can travel through logs, tool arguments and retrieved snippets as well as the visible answer.
- Excessive Agency. The model can call tools or trigger actions, and has more functionality, permission or autonomy than the task needs, so a confused or manipulated output causes real damage.
- Supply Chain. Third-party models, datasets, adapters and conversion tools that have been tampered with or are simply vulnerable.
- Data and Model Poisoning. Someone manipulates training, fine-tuning or retrieval data, or the model files themselves, to plant hidden behaviour, bias or a backdoor.
- Unbounded Consumption. No adequate limits on how much the model is used, which allows denial of service, runaway costs or copying a model’s behaviour through mass queries.
- Misinformation. Wrong or unsupported output that looks credible enough for a person, a workflow or an agent to act on.
- Hidden Context Exposure. Attackers extract or infer material the user was never meant to see, such as the system prompt, tool definitions or retrieved policy text. This replaces System Prompt Leakage.
- Vector and Embedding Weaknesses. Flaws in the search layer that decides what the model sees, as in retrieval augmented generation (RAG), where documents are fetched by similarity and added to the prompt.
- Improper Output Handling. Model output is passed to a browser, database, shell or other system without validation. That can let an attacker run script in another user’s browser (cross-site scripting), make a server contact an address of the attacker’s choosing (server-side request forgery) or run commands.
What Changed In 2026
The table lines up each risk across the two editions. The names are OWASP’s own.
| Risk | 2025 | 2026 | Movement |
|---|---|---|---|
| Prompt Injection | LLM01 | LLM01 | Unchanged |
| Sensitive Information Disclosure | LLM02 | LLM02 | Unchanged |
| Excessive Agency | LLM06 | LLM03 | Up three places |
| Supply Chain | LLM03 | LLM04 | Down one |
| Data and Model Poisoning | LLM04 | LLM05 | Down one |
| Unbounded Consumption | LLM10 | LLM06 | Up four places |
| Misinformation | LLM09 | LLM07 | Up two places |
| System Prompt Leakage, now Hidden Context Exposure | LLM07 | LLM08 | Renamed, broadened, down one |
| Vector and Embedding Weaknesses | LLM08 | LLM09 | Down one |
| Improper Output Handling | LLM05 | LLM10 | Down five places |
Three moves stand out. Excessive Agency rose to third, which the project leads call the most consequential change, because damage increasingly lands where models can take actions. Unbounded Consumption climbed four places because practitioners now rate cost and resource exhaustion more highly. Improper Output Handling fell furthest, from fifth to tenth.4 The 2026 Unbounded Consumption entry also explains why cost has become a security issue: reasoning models, image and audio input, and chains of tool calls can each make a single request far more expensive.5
A fall in rank is not a sign that a risk has gone away. Improper Output Handling still covers the classic web flaws that appear when model output reaches a browser or a database, and the 2026 entry now also includes insecure code produced by coding assistants.4
Several entries also grew in scope. Prompt Injection now explicitly covers instructions hidden in images or audio, Supply Chain covers model files that are not what they claim to be, and Data and Model Poisoning absorbs attempts to subvert fine-tuning.4
How The 2026 Ranking Was Built
Earlier editions were ranked by practitioner vote. For 2026 the team also gathered 7,714 real incidents from public vulnerability databases and an AI harm database, classified the 6,639 that had enough detail, and gave that evidence a quarter of the weight, with the vote carrying the rest.4
The two sources did not always agree. Ranked on raw incident counts alone, prompt injection would fall out of the top ten. The project leads read that as a sign that teams defend hard against it, so fewer clean exploits reach public databases, and they kept it first. Misinformation went the other way: voters placed it low, the incident record placed it high, and it ended up in the middle.4
Where This List Stops
The LLM Top 10 treats the model as a component inside your application. Once the model becomes an actor, with tools it calls on its own, memory that persists between sessions and actions with consequences, OWASP points readers to its separate Top 10 for Agentic Applications, announced in December 2025.46 We cover those risks in Agentic AI Security.
The list is also not a governance framework. It does not tell you who is accountable for an AI system or what a regulator expects. For that, see AI Governance And Regulation.
Using The List
A practical first use is a design review. For each LLM feature, walk the ten entries and ask whether the risk applies and which control covers it. The project leads’ letter that opens the 2026 edition asks teams to plan for failure: expect that someone will eventually manipulate the model, and make sure the permissions, checks and approvals around it keep that from turning into serious harm.4 The following articles in this group take the main risks in turn, starting with prompt injection.
Footnotes
-
OWASP GenAI Security Project, “OWASP GenAI LLM Top 10 2026”, resource page, 3 August 2026. genai.owasp.org ↩
-
OWASP GenAI Security Project, “OWASP Top 10 for LLM Applications 2026”, canonical Markdown source and release notes, released 4 August 2026, concept DOI 10.5281/zenodo.22109014. github.com ↩
-
OWASP GenAI Security Project, “OWASP Top 10 for LLM Applications 2025”, entry source files. github.com ↩
-
S. Wilson and R. Lambros, “Letter from the Project Leads”, OWASP Top 10 for LLM Applications 2026, August 2026. github.com ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
OWASP GenAI Security Project, “LLM06:2026 Unbounded Consumption”, OWASP Top 10 for LLM Applications 2026, August 2026. github.com ↩
-
OWASP GenAI Security Project, “Appendix A: Related Framework Mappings”, OWASP Top 10 for LLM Applications 2026, August 2026. github.com ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.