Browse by type

[!IMPORTANT] Current release: 2026 — published August 4, 2026.
Get the 2026 publication · Read the canonical source · Report a correction
This is the official source repository for the OWASP Top 10 for Large Language Model Applications, maintained as a core initiative of the OWASP GenAI Security Project.
The Top 10 is a community-developed awareness document for developers, architects, data scientists, security practitioners, and organizations building or operating applications that use large language models.
The 2026 release is complete. The publication combines community judgment with analysis of real-world incidents and updates the ordering, scope, examples, mitigations, and framework mappings across the list.
| Resource | Location |
|---|---|
| Official publication | Get the OWASP GenAI LLM Top 10 2026 |
| Canonical Markdown source | 2026/final/ |
| Release overview | 2026/README.md |
| Previous release | 2025/ |
2026/final/ — canonical source for the published 2026 release2026/working/ — historical working files and release-cycle tooling2025/ — source for the previous releasedocumentation/style/ — editorial and branding guidanceThe 2026 sprint plan and 2026/working/CONTRIBUTING.md are retained as records of the completed release process. They are not the current contribution workflow.
Post-release corrections and improvements are welcome. Use the 2026 release errata form for specific errors, broken links, or source/publication mismatches. Use the release feedback form for broader feedback or proposals for a future cycle.
[!IMPORTANT] All changes to this repository must be made through a pull request. Direct pushes to
mainare blocked by branch protection.
We have a working group channel on OWASP Slack: #team-genai-top-10-llm.
For the broader project contribution process, visit genai.owasp.org/contribute.
The 2026 edition is archived on Zenodo. Cite the concept DOI, which always resolves to the newest edition:
OWASP GenAI Security Project. (2026). OWASP Top 10 for Large Language Model Applications (Version 2026). OWASP Foundation. https://doi.org/10.5281/zenodo.22109014
To cite the 2026 edition specifically rather than the newest, use its version
DOI, 10.5281/zenodo.22109015.
CITATION.cff carries the same metadata in machine-readable
form, and GitHub renders it under "Cite this repository".
This project is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License.
$ claude mcp add GenAI-LLM-Top10 \
-- python -m otcore.mcp_server <graph>