OWASP Top 10 for LLM Applications 2025 — Unique AI Documentation

OWASP Top 10 for LLM Applications 2025

Purpose

The OWASP Top 10 is a widely recognized document outlining the most critical security risks facing web applications. Specifically focusing on LLM (Large Language Model) applications, these risks encompass vulnerabilities that could compromise the integrity, availability, and confidentiality of data processed by such models. This page outlines Unique’s understanding and approach on how to mitigate these risks to ensure the security and trustworthiness of our services.

All answers refer to Version 2025 of the OWASP Top 10 for LLM Applications

Unique’s approach to OWASP Top 10 for LLM Applications

LLM01: Prompt injections

Prompt Injection Vulnerabilities in LLMs involve crafty inputs leading to undetected manipulations. These inputs can affect the model even if they are imperceptible to humans. The impact ranges from data exposure to unauthorized actions, serving attackers' goals.

Prevention and Mitigation Strategies

LLM02: Sensitive Information Disclosure

LLM applications risk exposing sensitive data, proprietary algorithms, or confidential details through their output. This can result in unauthorized access to sensitive data, intellectual property breaches, and privacy violations.

Prevention and Mitigation Strategies

LLM03: Supply Chain

LLM supply chains are susceptible to various vulnerabilities, which can affect the integrity of training data, models, and deployment platforms. These risks can result in biased outputs, security breaches, or system failures.

Prevention and Mitigation Strategies

LLM04: Training Data Poisoning

Data poisoning occurs when pre-training, fine-tuning, or embedding data is manipulated to introduce vulnerabilities, backdoors, or biases. This manipulation can compromise model security, performance, or ethical behavior, leading to harmful outputs or impaired capabilities.

Prevention and Mitigation Strategies

LLM05: Improper Output Handling

Improper Output Handling refers to insufficient validation, sanitization, and handling of the outputs generated by large language models before they are passed downstream to other components and systems. Successful exploitation can result in XSS and CSRF in web browsers as well as SSRF, privilege escalation, or remote code execution on backend systems.

Prevention and Mitigation Strategies

LLM06: Excessive Agency

An LLM-based system is often granted a degree of agency through extensions, tools, skills, or plugins to undertake actions in response to prompts. In agent-based systems, the model makes repeated calls to LLMs using output from previous invocations to ground and direct subsequent ones.

Prevention and Mitigation Strategies

LLM07: System Prompt Leakage

The system prompt leakage vulnerability in LLMs refers to the risk that the system prompts or instructions used to steer the behavior of the model can also contain sensitive information that was not intended to be discovered. When discovered, this information can be used to facilitate other attacks.

Prevention and Mitigation Strategies

LLM08: Vector and Embedding Weaknesses

Vectors and embeddings vulnerabilities present significant security risks in systems utilizing Retrieval Augmented Generation (RAG) with Large Language Models (LLMs). Weaknesses in how vectors and embeddings are generated, stored, or retrieved can be exploited to inject harmful content, manipulate model outputs, or access sensitive information.

Prevention and Mitigation Strategies

LLM09: Misinformation

Misinformation from LLMs poses a core vulnerability for applications relying on these models. Misinformation occurs when LLMs produce false or misleading information that appears credible. This vulnerability can lead to security breaches, reputational damage, and legal liability.

Prevention and Mitigation Strategies

LLM10: Unbounded Consumption

Unbounded Consumption occurs when a Large Language Model (LLM) application allows users to conduct excessive and uncontrolled inferences, leading to risks such as denial of service (DoS), economic losses, model theft, and service degradation. The high computational demands of LLMs make them vulnerable to resource exploitation.

Prevention and Mitigation Strategies

Conclusion

Unique is committed to maintaining the highest security standards in our LLM applications. By proactively addressing the OWASP Top 10 for LLM Applications 2025, we ensure that our systems remain secure, reliable, and trustworthy. Our human-in-the-loop approach serves as a critical foundation across all security domains, complemented by technical safeguards, governance frameworks, and continuous monitoring to protect against emerging threats in the rapidly evolving field of large language models.