LLM01
Prompt Injection
103 CVEs
CRITICAL CVE-2026-54769
CVSS 10.0 Langroid: prompt injection to RCE via broken eval() sandbox
CRITICAL CVE-2026-61447
CVSS 10.0 PraisonAI: RCE via unsandboxed LLM code execution
+ 100 more CVEs mapped to this control
LLM02
Sensitive Information Disclosure
234 CVEs
CRITICAL CVE-2026-34938
CVSS 10.0 praisonaiagents: sandbox bypass enables full host RCE
CRITICAL CVE-2026-61447
CVSS 10.0 PraisonAI: RCE via unsandboxed LLM code execution
CRITICAL CVE-2026-33663
CVSS 10.0 n8n: member role steals plaintext HTTP credentials
+ 231 more CVEs mapped to this control
LLM03
Supply Chain Vulnerabilities
199 CVEs
CRITICAL CVE-2026-69083
CVSS 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
CRITICAL CVE-2026-7873
CVSS 9.9 Langflow: authenticated RCE enables credential theft
CRITICAL CVE-2026-25115
CVSS 9.9 n8n: Protection Bypass circumvents security controls
+ 196 more CVEs mapped to this control
LLM04
Data and Model Poisoning
195 CVEs
CRITICAL CVE-2025-53002
CVSS 9.8 LLaMA-Factory: RCE via unsafe checkpoint deserialization
CRITICAL CVE-2026-55450
CVSS 9.3 Langflow: unauthenticated upload → DoS + path disclosure
+ 192 more CVEs mapped to this control
LLM05
Improper Output Handling
264 CVEs
CRITICAL CVE-2025-71338
CVSS 10.0 Flowise: unauthenticated file write enables RCE
+ 261 more CVEs mapped to this control
LLM06
Excessive Agency
502 CVEs
CRITICAL CVE-2026-67429
CVSS 10.0 flyto-core: arbitrary file write via bypassed path guard
CRITICAL CVE-2026-33663
CVSS 10.0 n8n: member role steals plaintext HTTP credentials
CRITICAL CVE-2026-46695
CVSS 10.0 Boxlite: read-only bypass enables host code execution
+ 499 more CVEs mapped to this control
LLM07
System Prompt Leakage
388 CVEs
CRITICAL CVE-2026-39888
CVSS 10.0 praisonaiagents: sandbox escape enables host RCE
CRITICAL CVE-2026-10134
CVSS 10.0 Langflow: unauthenticated RCE via tool_code injection
+ 385 more CVEs mapped to this control
LLM08
Vector and Embedding Weaknesses
357 CVEs
CRITICAL CVE-2026-39888
CVSS 10.0 praisonaiagents: sandbox escape enables host RCE
CRITICAL CVE-2026-48168
CVSS 10.0 PraisonAI: shell injection in Claude Action enables RCE
+ 354 more CVEs mapped to this control
LLM09
Misinformation
20 CVEs
CRITICAL CVE-2025-61260
CVSS 9.8 OpenAI Codex CLI: RCE via malicious MCP config files
CRITICAL CVE-2024-39236
CVSS 9.8 Gradio: code injection via component metadata (CVSS 9.8)
+ 17 more CVEs mapped to this control
LLM10
Unbounded Consumption
47 CVEs
HIGH GHSA-5qw8-f2g9-ff29
CVSS 8.2 PraisonAI: auth bypass exposes recipe API to unauthenticated callers
HIGH CVE-2025-2099
CVSS 7.5 transformers: ReDoS in testing_utils causes DoS
+ 44 more CVEs mapped to this control
Download Full Evidence Pack
Get the complete OWASP LLM Top 10 evidence pack with all CVE-to-control mappings,
rationale, and audit-ready documentation. Exportable as CSV.
Get Evidence Pack