OWASP's 2025 LLM risks: security beyond the prompt

Released in November 2024, the updated list covers system prompt leakage, vector and embedding weaknesses, and resource consumption.

Contents of this article

What happened

The OWASP Top 10 for LLM Applications 2025 document records November 18, 2024 as its release date. Risks include system prompt leakage, vector and embedding weaknesses, and unbounded consumption, directing attention to the data, tools and permissions surrounding a model.

Implications for website operations

In a knowledge-backed AI service, answer quality and data authorization are separate concerns. A correct answer may still reveal material the account cannot access, and a well-formed tool request may exceed its business permissions. System prompts should not be the only authorization boundary.

Operational next steps

Test cross-account isolation, tool authorization, output handling and invocation cost separately. Enforce server-side permissions for high-impact actions and retain an audit trail from the request through actual tool execution.

Official source

Read the official publication

Back to industry insights Contact technical support