The rapid integration of Large Language Models (LLMs) and generative AI agents into enterprise web applications has introduced an entirely new attack surface. While developers treat LLMs as conversational assistants, attackers treat them as untrusted execution environments that can be manipulated through adversarial inputs.
OWASP Top 10 for LLM: primary attack vectors
Security assessments of AI-enabled web applications evaluate several high-risk vulnerability categories:
- Prompt Injection (LLM01): direct and indirect prompt manipulation that overrides developer system instructions to exfiltrate private instructions or trigger unauthorized actions.
- Insecure Output Handling (LLM02): rendering LLM output directly into the DOM or passing it to backend SQL/shell interpreters without sanitization, leading to XSS or command execution.
- Excessive Agency & Insecure Tool Calling (LLM08): granting AI agents autonomous access to internal APIs, databases, or email tools without human-in-the-loop confirmation.
- Server-Side Request Forgery via AI (SSRF): tricking document-processing AI models into fetching internal cloud metadata URLs or private network resources.
Defending LLM integrations
Never trust LLM output. Treat all text produced by language models as untrusted user input subject to standard encoding, validation, and parameterization. Restrict agent tool permissions with fine-grained API scopes and require explicit user approval for destructive actions.
An LLM is not a security boundary. Treat model inputs and outputs with the same rigorous validation applied to public web forms.