# OWASP LLM Top 10: Security Risk Reference for AI Application Builders

> The OWASP Top 10 for Large Language Model Applications is a community-maintained security risk list for teams building LLM-powered systems; the original repository now serves as a historical archive while active development continues at GenAI-Security-Project/GenAI-LLM-Top10.

**OWASP/www-project-top-10-for-large-language-model-applications** — OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

- Repository: https://github.com/OWASP/www-project-top-10-for-large-language-model-applications
- Website: http://genai.owasp.org
- Stars: 1,426 · Forks: 359
- Language: Python
- License: NOASSERTION
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/owasp-www-project-top-10-for-large-language-model-applications

## A Risk List Built for LLM Application Developers

When teams started deploying LLM-backed applications at scale, the existing OWASP web application security guidance did not map cleanly onto the failure modes specific to language models: prompt injection, insecure output handling, training data poisoning, and excessive model permissions have no direct equivalents in the traditional OWASP Top 10 for web applications.

The OWASP Top 10 for Large Language Model Applications fills that gap. It provides a prioritized list of security risks specific to systems that incorporate large language models, written for developers, architects, and security reviewers who need to evaluate LLM-backed products. The project is part of the broader OWASP GenAI Security Project, which develops freely available guidance for securing generative AI systems.

## Repository Status: Legacy Archive, Active Development Moved

The README of the original repository states this directly: the repository is maintained as a legacy entry point and historical archive. Active development has moved to GenAI-Security-Project/GenAI-LLM-Top10. The current release is the OWASP GenAI LLM Top 10 2026, published on August 4, 2026, and accessible at genai.owasp.org.

The original repository remains available so that existing links, citations, and historical artifacts continue to resolve. Earlier releases, translations, and working files are preserved in the Archive/ directory. New issues, pull requests, and release work should be filed at the active repository, not here.

This distinction matters for practical use. If you are citing the list in documentation, link to genai.owasp.org or the active repository. If you are contributing a correction to the 2026 release, file it using the release-errata template at GenAI-Security-Project/GenAI-LLM-Top10. If you are reading historical versions, such as the 2023 v1.1 release, those are available in the Archive/ directory of this legacy repository.

## What the Releases Cover and How They Are Structured

The project follows an annual release cycle. The repository records three releases: the 2026 edition published August 4, 2026; the 2025 edition archived as a prior release; and the original 2023 v1.1 and v1 editions. Each release names and ranks ten security risks specific to LLM applications, provides descriptions of each risk, explains impact and likelihood considerations, and offers mitigation guidance.

The 2026 release is titled the OWASP GenAI LLM Top 10, reflecting the project's expansion from standalone LLM applications to the broader generative AI system category, which includes agentic architectures and LLM pipelines. The project also documents a separate OWASP Top 10 for Agentic Applications, according to the related searches associated with this work.

The content lives in markdown files and is rendered as a documentation site at genai.owasp.org. The repository structure includes a 2_0_vulns/ directory for working files, a resources/ directory, and an Archive/ directory for historical materials. Translations of earlier releases are in the Archive/ directory as well.

## How to Use the List in a Security Review

The OWASP LLM Top 10 is a reference document, not an automated scanning tool. A typical use is as a checklist during a threat modeling or security review session. A team building an LLM-backed application would work through the ten risk categories, assess whether each applies to their architecture, and document mitigations for those that do.

The list is widely referenced in LLM application security audits and procurement questionnaires. Several organizations use it as the basis for security requirements documents when evaluating LLM-powered third-party tools. The OWASP Slack workspace has a #team-genai-top-10-llm channel for contributors and practitioners working with the material.

The project is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0), which allows redistribution and adaptation as long as attribution is preserved and derivative works carry the same license. This makes it suitable for inclusion in internal security policy documents, training materials, and audit frameworks.

## Limitations: No Tooling, No Code, and a Moving Target

The OWASP LLM Top 10 is documentation. It does not include a testing framework, a scanner, or proof-of-concept exploit code. Teams who need to demonstrate a vulnerability, not just name it, will need to look elsewhere for tooling.

The list also reflects the state of LLM application security at the time of each annual release. The field moves quickly: new attack patterns, new deployment architectures, and new model capabilities change the risk surface between releases. The 2023 v1 content is preserved, but some of its framing has already been updated in the 2025 and 2026 editions. Teams using the list should verify which version they are referencing and whether a newer edition has revised the risk they are examining.

A natural comparison point is the NIST AI Risk Management Framework (AI RMF), which provides a broader organizational governance structure for AI risk. The OWASP LLM Top 10 is more specific and more actionable for application security teams: it names concrete attack classes rather than governance categories. The two documents are complementary rather than competing.

## Contributing and Staying Current

Contributions to the current content should go to GenAI-Security-Project/GenAI-LLM-Top10. The original OWASP repository no longer accepts release work. The active repository provides issue templates for reporting corrections (release-errata.yml) and submitting broader feedback (release-feedback.yml). The working group is accessible on the OWASP Slack at #team-genai-top-10-llm and the broader contribution process is documented at genai.owasp.org/contribute.

For teams that need a static copy of the current release, the 2026 publication is available as a downloadable PDF from genai.owasp.org. The source text for the 2026 final release is at GenAI-Security-Project/GenAI-LLM-Top10/tree/main/2026/final.

## Conclusion

The OWASP LLM Top 10 is the reference point for application security teams who need a shared vocabulary and prioritized risk list when auditing LLM-powered systems. It is not a technical control library or a testing framework. Teams doing hands-on penetration testing of LLM applications should supplement it with dedicated tooling. Readers who want the current content should go directly to genai.owasp.org, since the GitHub repository described here is now a legacy archive; contributions and corrections should be filed at GenAI-Security-Project/GenAI-LLM-Top10.

## FAQ

### What are the top 10 attacks on LLMs according to OWASP?

The current OWASP GenAI LLM Top 10 2026 is published at genai.owasp.org; the risk categories evolve with each annual release and include prompt injection, insecure output handling, and training data poisoning among others. Earlier versions from 2023 and 2025 are archived in this repository's Archive/ directory.

### Is the OWASP LLM Top 10 GitHub repository still actively updated?

The original repository is now a legacy archive. The README states that active development has moved to GenAI-Security-Project/GenAI-LLM-Top10, and new contributions and corrections should be filed there.

### What license does the OWASP LLM Top 10 use?

The project is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0), which allows redistribution and adaptation with attribution and the same license on derivative works.

## Sources

- [Issues](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/issues)
- [OWASP/www-project-top-10-for-large-language-model-applications on GitHub](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications)
- [Project website](http://genai.owasp.org)
- [README](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/blob/main/README.md)
- [Releases](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/owasp-www-project-top-10-for-large-language-model-applications
