The OWASP LLM Top 10 2025 is the updated edition of OWASP’s ranked list of the most critical security risks for applications built on large language models. It catalogs threats such as prompt injection, sensitive information disclosure, supply-chain vulnerabilities, excessive agency, and improper output handling, with guidance on mitigation. The list is a widely referenced baseline for securing LLM and agentic AI systems.

Content

  • It enumerates risks including prompt injection, sensitive data disclosure, supply-chain compromise, excessive agency, and unsafe output handling, each with mitigation guidance. As agentic systems gain real-world capabilities, the list serves as a shared reference for threat modeling and secure design.