AIToday
Large Language ModelsAI Safety & AlignmentVentureBeat AIPublished: Aug 26, 2026, 04:01 JST2 min read

Prompt injection ranks No.1 on OWASP, No.12 in real incidents

Prompt injection ranks No.1 on OWASP, No.12 in real incidents

Key takeaway

  • Prompt injection is the top OWASP risk for LLM apps but ranks No. 12 in real incidents.

  • The gap reflects visibility, not danger.

  • The attack is invisible to vulnerability scanners.

3 Key Points

  1. What happened

    A study by two leaders of the OWASP Top 10 for LLM Applications, Kyriakos "Rock" Lambros and Steve Wilson, compared the list against 6,639 labeled real-world incidents and found prompt injection ranks No. 12 in actual incidents, despite holding the No. 1 spot on the OWASP list for three consecutive years.

  2. Why it matters

    The researchers say the drop measures visibility rather than danger, because prompt injection operates where a vulnerability scanner cannot see it. A CISO who sees a low CVE count and deprioritizes prompt injection is reading the scoreboard wrong.

  3. What to watch

    The analysis is exploratory, not peer reviewed, and not the official OWASP release. It is based on 7,714 LLM security incidents from sources like CVE, GitHub Security Advisories, OSV, and the AIAAIC AI-harm database, with 6,639 labeled against a 20-entry taxonomy.

Ask the AI about this article →

Context & Analysis

The OWASP Top 10 for LLM Applications has listed prompt injection as the top risk for three years, reflecting its theoretical severity. But when two project leaders checked the list against real-world incidents, they found it appears less frequently in labeled events—at No. 12. This does not mean prompt injection is less dangerous; rather, it suggests that current vulnerability scanning methods often miss it, so it goes underreported in incident databases.

The study's data comes from multiple sources, including CVE and the AIAAIC AI-harm database, covering 7,714 incidents, of which 6,639 were labeled. Because the analysis is exploratory and not official, its findings should be seen as a signal for deeper investigation rather than a revision of the OWASP list. For security leaders, the key takeaway is that low CVE counts are not a reliable measure of risk for prompt injection.

FAQ

Why does prompt injection rank lower in real incidents than on the OWASP list?
The drop measures visibility rather than danger, because the attack operates where a vulnerability scanner cannot see it.
Is this study an official OWASP release?
No, the analysis is exploratory, not peer reviewed, and not the official OWASP release. The authors state it does not supersede the official list or its process.
VentureBeat AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • DataAgent launches with $10M to auto-fix Kubernetes faultsSiliconANGLE AI · 36m ago
  • SK Hynix custom HBM boosts inference up to 5.15xDIGITIMES Asia · 36m ago
  • Nvidia Earnings: Boring by Design, Avoiding a Consolidated WorldStratechery (Ben Thompson) · 36m ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleAnthropic merges Claude chat and Cowork memory