OWASP LLM Top 10 Compliance Tracker

The OWASP Top 10 for LLM Applications identifies the most critical security risks for applications using Large Language Models. Each risk category below is mapped to real CVEs affecting AI/ML packages in production.

3000
CVEs Mapped
10
Controls with CVEs
3719
Total Mappings

Controls & Mapped Vulnerabilities

LLM01

Prompt Injection

103 CVEs
CRITICAL
CVE-2026-54769 CVSS 10.0

Langroid: prompt injection to RCE via broken eval() sandbox

CRITICAL
CVE-2026-61447 CVSS 10.0

PraisonAI: RCE via unsandboxed LLM code execution

CRITICAL
CVE-2026-61539 CVSS 10.0

Xinference: eval() on LLM output enables RCE

+ 100 more CVEs mapped to this control

LLM02

Sensitive Information Disclosure

234 CVEs
CRITICAL
CVE-2026-34938 CVSS 10.0

praisonaiagents: sandbox bypass enables full host RCE

CRITICAL
CVE-2026-61447 CVSS 10.0

PraisonAI: RCE via unsandboxed LLM code execution

CRITICAL
CVE-2026-33663 CVSS 10.0

n8n: member role steals plaintext HTTP credentials

+ 231 more CVEs mapped to this control

LLM03

Supply Chain Vulnerabilities

199 CVEs
CRITICAL
CVE-2026-69083 CVSS 10.0

SiYuan: unauthenticated SQLi in full-text search endpoint

CRITICAL
CVE-2026-7873 CVSS 9.9

Langflow: authenticated RCE enables credential theft

CRITICAL
CVE-2026-25115 CVSS 9.9

n8n: Protection Bypass circumvents security controls

+ 196 more CVEs mapped to this control

LLM04

Data and Model Poisoning

195 CVEs
CRITICAL
CVE-2025-53002 CVSS 9.8

LLaMA-Factory: RCE via unsafe checkpoint deserialization

CRITICAL
CVE-2026-55450 CVSS 9.3

Langflow: unauthenticated upload → DoS + path disclosure

CRITICAL
CVE-2026-27493 CVSS 9.0

n8n: Code Injection enables RCE

+ 192 more CVEs mapped to this control

LLM05

Improper Output Handling

264 CVEs
CRITICAL
CVE-2025-71338 CVSS 10.0

Flowise: unauthenticated file write enables RCE

CRITICAL
CVE-2026-61539 CVSS 10.0

Xinference: eval() on LLM output enables RCE

CRITICAL
CVE-2026-26030 CVSS 10.0

semantic-kernel: Code Injection enables RCE

+ 261 more CVEs mapped to this control

LLM06

Excessive Agency

502 CVEs
CRITICAL
CVE-2026-67429 CVSS 10.0

flyto-core: arbitrary file write via bypassed path guard

CRITICAL
CVE-2026-33663 CVSS 10.0

n8n: member role steals plaintext HTTP credentials

CRITICAL
CVE-2026-46695 CVSS 10.0

Boxlite: read-only bypass enables host code execution

+ 499 more CVEs mapped to this control

LLM07

System Prompt Leakage

388 CVEs
CRITICAL
CVE-2026-39888 CVSS 10.0

praisonaiagents: sandbox escape enables host RCE

CRITICAL
CVE-2026-10134 CVSS 10.0

Langflow: unauthenticated RCE via tool_code injection

CRITICAL
CVE-2026-26030 CVSS 10.0

semantic-kernel: Code Injection enables RCE

+ 385 more CVEs mapped to this control

LLM08

Vector and Embedding Weaknesses

357 CVEs
CRITICAL
CVE-2026-39888 CVSS 10.0

praisonaiagents: sandbox escape enables host RCE

CRITICAL
CVE-2026-26030 CVSS 10.0

semantic-kernel: Code Injection enables RCE

CRITICAL
CVE-2026-48168 CVSS 10.0

PraisonAI: shell injection in Claude Action enables RCE

+ 354 more CVEs mapped to this control

LLM09

Misinformation

20 CVEs
CRITICAL
CVE-2025-61260 CVSS 9.8

OpenAI Codex CLI: RCE via malicious MCP config files

CRITICAL
CVE-2024-39236 CVSS 9.8

Gradio: code injection via component metadata (CVSS 9.8)

HIGH
GHSA-m3mh-3mpg-37hw CVSS 8.6

OpenClaw: .npmrc hijack enables RCE on plugin install

+ 17 more CVEs mapped to this control

LLM10

Unbounded Consumption

47 CVEs
HIGH
GHSA-5qw8-f2g9-ff29 CVSS 8.2

PraisonAI: auth bypass exposes recipe API to unauthenticated callers

HIGH
GHSA-52vm-mxx8-f227 CVSS 7.7

Phantom MCP: unconfined output path enables file write

HIGH
CVE-2025-2099 CVSS 7.5

transformers: ReDoS in testing_utils causes DoS

+ 44 more CVEs mapped to this control

Download Full Evidence Pack

Get the complete OWASP LLM Top 10 evidence pack with all CVE-to-control mappings, rationale, and audit-ready documentation. Exportable as CSV.

Get Evidence Pack