OWASP's 2025 LLM risks: security beyond the prompt
Released in November 2024, the updated list covers system prompt leakage, vector and embedding weaknesses, and resource consumption.
Contents of this article
What happened
The OWASP Top 10 for LLM Applications 2025 document records November 18, 2024 as its release date. Risks include system prompt leakage, vector and embedding weaknesses, and unbounded consumption, directing attention to the data, tools and permissions surrounding a model.
Implications for website operations
In a knowledge-backed AI service, answer quality and data authorization are separate concerns. A correct answer may still reveal material the account cannot access, and a well-formed tool request may exceed its business permissions. System prompts should not be the only authorization boundary.
Operational next steps
Test cross-account isolation, tool authorization, output handling and invocation cost separately. Enforce server-side permissions for high-impact actions and retain an audit trail from the request through actual tool execution.
