← Security Hub guides

LLM SECURITY / THE TOP 10 SERIES

Top 10 LLM security issues: a practical guide

The OWASP 2025 LLM risk categories explained with practical checks for applications, retrieval, agents, and model operations.

Truva Solutions · Guide · 19 Sep 2026

Read the practical guide ↓
10 LLM security issues. A numbered overview; every issue and action is explained in the article below.
Truva Solutions · Security Hub© 2026 TRUVA SOLUTIONSDownload infographic ↓

Before you start

This guide follows the names and order of the OWASP Top 10 for LLM Applications, 2025 edition. The short explanations and implementation checks are Truva’s editorial guidance. Numbering is not a prediction of risk in your environment.

A model is only one part of an LLM application. Evaluate how inputs enter, which information retrieval exposes, how outputs are used, and what connected tools can do. Controls belong at those boundaries as well as in model evaluation.

01

Prompt Injection

Instructions in prompts or external content can steer the model away from the intended task.

Keep untrusted input from authorizing actions.

Test malicious retrieved content. Enforce tool permissions and sensitive-action approvals outside the model.

Primary source ↗
02

Sensitive Information Disclosure

An answer can expose information the recipient should not receive.

Limit sensitive information in context.

Minimize sensitive inputs, apply retrieval permissions, and review provider retention and logging settings.

Primary source ↗
03

Supply Chain

Third-party code, model artifacts, and data introduce dependencies that require review.

Verify models, packages, and providers.

Record versions and provenance. Isolate evaluation and prevent unreviewed dependencies from reaching production credentials.

Primary source ↗
04

Data and Model Poisoning

Manipulated data or model components can introduce unwanted behavior that ordinary use may not reveal.

Validate changes to training and data sources.

Control ingestion and update permissions; track provenance and compare evaluation results after changes.

Primary source ↗
05

Improper Output Handling

Model output becomes dangerous when downstream software treats it as safe code, markup, or commands.

Treat generated output as untrusted.

Validate output types and apply context-appropriate escaping. Never execute generated commands merely because the model produced them.

Primary source ↗
06

Excessive Agency

An agent can cause larger harm when it has unnecessary capabilities or can act without appropriate review.

Limit tools, permissions, and autonomy.

Prefer narrowly scoped tools and identities. Require approval for consequential actions and bound execution.

Primary source ↗
07

System Prompt Leakage

Hidden instructions may be disclosed. Their secrecy should not be the control protecting sensitive systems.

Keep secrets and authorization outside prompts.

Remove credentials and sensitive policy details from prompts. Enforce access rules in application code.

Primary source ↗
08

Vector and Embedding Weaknesses

Shared indexes can retrieve documents across access boundaries or surface manipulated material.

Make retrieval permission-aware.

Partition and filter by authorized identity; test cross-tenant retrieval and changes to document permissions.

Primary source ↗
09

Misinformation

A fluent answer can still be inaccurate, incomplete, or unsupported.

Verify important answers against evidence.

Evaluate on representative tasks, verify references, and require human review where incorrect answers could cause significant harm.

Primary source ↗
10

Unbounded Consumption

Expensive inputs or repeated model and tool calls can exhaust capacity and increase cost.

Bound requests, runtime, and spend.

Set quotas, token and step limits, timeouts, and budget alerts. Test behavior when limits are reached.

Primary source ↗

Turn findings into verified fixes.

Start with your most exposed or sensitive workflow. Confirm the issue, assign an owner, make a controlled change, and keep evidence from the retest. These checks are a starting point, not proof of complete security or compliance.

Discuss a security assessment

Category names and order attributed to OWASP Top 10 for LLM Applications (2025). OWASP content is available under CC BY-SA 4.0. This article’s adaptation and infographic are offered under the same license; Truva’s trademarks are excluded.

Join the discussion

Page views

What are you seeing in your AI or cloud environment? Share a question or a practical lesson.

Comments are reviewed before publication. Your display name and comment will be public if approved. Please leave out confidential or personal information.

Enable JavaScript to read and submit comments.