OWASP LLM01: prompt injection
The OWASP Top 10 for LLM Applications 2025 ranks prompt injection first. This page summarises the LLM01:2025 entry in our own words and shows how the prompt injection test maps to it.
The 2025 list
| ID | Risk |
|---|---|
| LLM01:2025 | Prompt Injection |
| LLM02:2025 | Sensitive Information Disclosure |
| LLM03:2025 | Supply Chain |
| LLM04:2025 | Data and Model Poisoning |
| LLM05:2025 | Improper Output Handling |
| LLM06:2025 | Excessive Agency |
| LLM07:2025 | System Prompt Leakage |
| LLM08:2025 | Vector and Embedding Weaknesses |
| LLM09:2025 | Misinformation |
| LLM10:2025 | Unbounded Consumption |
What LLM01 covers
- Direct prompt injection: the user's input changes the model's behaviour, on purpose or by accident.
- Indirect prompt injection: content from external sources such as websites or files changes it.
- Not limited to visible text: OWASP notes the injected content need not be human-readable, as long as the model parses it, and that multimodal models add cross-modal risks.
- RAG and fine-tuning make outputs more relevant but, per OWASP, do not fully mitigate the risk.
The nine scenarios
Direct injection · Indirect injection · Unintentional injection · Intentional model influence · Code injection · Payload splitting · Multimodal injection · Adversarial suffix · Multilingual or obfuscated attack. Each is summarised with its documented case on the examples page.
The seven mitigations
- Constrain model behaviour
- Define and validate expected output formats
- Implement input and output filtering
- Enforce privilege control and least privilege access
- Require human approval for high-risk actions
- Segregate and identify external content
- Conduct adversarial testing and attack simulations
How to apply each one: how to prevent prompt injection attacks.
Related entries
| Entry | How it connects to LLM01 | Test family |
|---|---|---|
| LLM02 Sensitive Information Disclosure | What an injection often extracts | Tool-call exfiltration, secret disclosure |
| LLM05 Improper Output Handling | Rendered links and images, or executed output, carry the attack further | Markdown image and link exfiltration |
| LLM06 Excessive Agency | Tools and permissions decide how much damage an injection does | Tool-call exfiltration |
| LLM07 System Prompt Leakage | Anything in the prompt can be extracted | Secret and system prompt disclosure |
Sources
Questions
What is OWASP LLM01?
LLM01:2025 Prompt Injection is the first entry in the OWASP Top 10 for LLM Applications 2025. It covers inputs, direct or from external content, that alter a model's behaviour in unintended ways.
Which OWASP entries relate to LLM01?
LLM02 Sensitive Information Disclosure, LLM05 Improper Output Handling, LLM06 Excessive Agency and LLM07 System Prompt Leakage describe what an injection can lead to or exploit.