vulns.co
/
GKData.io MCP

OWASP Gen AI Security Project · 1 min read

OWASP LLM05:2025: generated-output consumer trust

Explains why model-generated content remains untrusted when passed to browsers, databases or backend functions. The relevant boundary is the consuming component: plausible model text must not acquire executable meaning or greater authority merely because an application generated it. Distinguishes unsafe downstream handling from general reliance on answer accuracy.

Open the reference Implementation GuideReviewed 2026-10-03

How to use this reference

Map each output consumer in an owned AI application to its validation and encoding contract. Prefer parameterized database operations and context-aware encoding, with monitoring and browser policy controls as supplementary layers.

Before reading

  • Basic LLM application data flow
  • Context-sensitive encoding and separation of data from executable interpretation

Context and limits

  • The 2025 designation is an edition identifier, not a verified publication date.
  • The source contains attack scenarios; this record retains only trust-boundary and remediation concepts.
  • This category describes possible failure modes rather than current exposure of a particular product.

Related visual models

Sources and provenance

  1. LLM05:2025 Improper Output Handling OWASP Gen AI Security Project · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software