Letter from the Project Leads
The OWASP Top 10 for Large Language Model Applications started in 2023 as a community-driven effort to highlight and address security issues specific to AI applications. As LLMs are embedded more deeply in everything from customer interactions to internal operations, developers and security professionals keep discovering new vulnerabilities — and ways to counter them.
The 2023 list built a foundation for secure LLM usage; the 2025 version was shaped by a larger, more diverse group of global contributors through brainstorming, voting and real-world feedback from professionals in the thick of LLM application security.
What's New in the 2025 Top 10
The 2025 list reflects a deeper understanding of existing risks and introduces critical updates on how LLMs are used in real-world applications today.
- Unbounded Consumption expands what was previously Denial of Service to include resource management and unexpected costs — a pressing issue in large-scale LLM deployments.
- Vector and Embedding Weaknesses is a new entry responding to requests for guidance on securing Retrieval-Augmented Generation (RAG) and other embedding-based methods.
- System Prompt Leakage is a new entry addressing real-world exploits: developers cannot safely assume information in system prompts remains secret.
- Excessive Agency has been expanded, given the rise of agentic architectures where unchecked permissions can lead to unintended or risky actions.
Moving Forward
Like the technology itself, this list is a product of the open-source community's insights and experience — shaped by developers, data scientists and security experts committed to building safer AI applications.
Project Lead: Steve Wilson · Technical & Vulnerability Entries Lead: Ads Dawson. Traditional Chinese translation led by Talesh Seeparsan with Henry Hu (胡辰澔), Will Huang (黃保翕) and Yingzi Jin — a fully human translation chosen given the topic's technical and critical nature.