vulns.co
/
GKData.io MCP

OWASP Gen AI Security Project · 1 min read

OWASP LLM08:2025: retrieval permissions and knowledge provenance

Examines security assumptions around retrieval-augmented generation, including access to embeddings, cross-context disclosure and integrity of imported knowledge. Shared retrieval infrastructure must preserve the distinctions between users and data classifications. Source validation and retrieval records help explain which knowledge entered a response and whether access was appropriate.

Open the reference Architecture GuideReviewed 2026-10-03

How to use this reference

For an owned RAG design, document dataset partitions and permission-aware retrieval, preserve source classifications when combining knowledge, and review ingestion integrity. Record retrieval events so confidentiality and provenance decisions remain reviewable.

Before reading

  • Basic concepts of embeddings, vector stores and retrieval-augmented generation
  • User, group and tenant access-control models

Context and limits

  • The 2025 designation is an edition identifier; publication and latest-update dates were not established.
  • This record focuses on permissions and provenance; it does not reproduce the source’s attack scenarios or quantify embedding reconstruction risk.
  • RAG grounding can improve relevance without establishing that retrieved content is authorized or trustworthy.

Sources and provenance

  1. LLM08:2025 Vector and Embedding Weaknesses OWASP Gen AI Security Project · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software