Skip to content

Migrate crosswalk to OWASP Top 10 for LLM Applications 2026 - #4

Merged
emmanuelgjr merged 2 commits into
mainfrom
update/llm-top10-2026
Aug 28, 2026
Merged

emmanuelgjr merged 2 commits into
mainfrom
update/llm-top10-2026

Conversation

@emmanuelgjr

Copy link
Copy Markdown
Contributor

Retargets the llm-top10/ mappings from the 2025 list to the 2026 final list.

Breaking change

Eight of the ten entries changed number, and the change is a permutation — an in-order find-and-replace will corrupt downstream references. MIGRATION.md carries the full map and a checklist for consumers.

LLM03→LLM04  LLM04→LLM05  LLM05→LLM10  LLM06→LLM03
LLM07→LLM08  LLM08→LLM09  LLM09→LLM07  LLM10→LLM06

source_list is now LLM-Top10-2026; crosswalk version 2026-Q3; package 4.0.0.

Renamed and re-scoped

Entry Change
LLM08 Hidden Context Exposure Was System Prompt Leakage. Widened from the system prompt to all non-user-facing context — developer instructions, retrieved policy text, and tool and function schemas
LLM10 Improper Output Handling Was Insecure Output Handling. Widened to cover insecure code generated by coding assistants at scale
LLM04 Supply Chain Was Supply Chain Vulnerabilities
LLM01 · LLM04 · LLM05 Scope notes for cross-modal payloads, artifact provenance, and fine-tuning subversion

Severity re-baselining

Three entries moved with their rank. Basis recorded in RATIONALE.md § 4.5, since the repo forbids severity changes without a cited source.

  • LLM03 Excessive Agency High → Critical (climbed to third, largest move on the list)
  • LLM06 Unbounded Consumption Medium → High (rose four places)
  • LLM07 Misinformation Medium → High (widest vote-versus-evidence gap)

Pre-existing bugs fixed along the way

LLM_DORA.md, LLM_FedRAMP.md, and LLM_SP800218A.md still carried entries from the 2023 list: a duplicate Model DoS shadowing Unbounded Consumption, Training Data Poisoning in place of Data and Model Poisoning, and quick-reference tables keyed to pre-2025 numbering. Each was remapped by entry name, the duplicate dropped, and the entries they never had were authored — LLM10 for DORA and FedRAMP, LLM02 for SP 800-218A. The same stale cross-references in the agentic and DSGAI counterparts were repaired the same way.

Verification

  • generate.js extracts 10/10 entries from all 23 LLM framework files
  • validate.js reports the same 51 errors and 67 warnings as main — all pre-existing, no regression
  • 12/12 package tests pass; tsc clean; compliance and incident reports build

Known, left out of scope

  • DSGAI02/DSGAI10 are mislabelled Training Data Poisoning in four DSGAI files and one PyRIT script — a separate list's naming bug
  • evals/garak/ has no probe for LLM03 Excessive Agency (it never had one for the old LLM06)

🤖 Generated with Claude Code

emmanuelgjr and others added 2 commits August 28, 2026 11:10
Retargets the llm-top10/ mappings from the 2025 list to the 2026 list
(https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/tree/main/2026/final).

Eight of the ten entries changed number, and the change is a permutation,
so downstream references cannot be updated with an in-order find-and-replace.
MIGRATION.md carries the full map and a checklist for consumers.

  LLM03->LLM04  LLM04->LLM05  LLM05->LLM10  LLM06->LLM03
  LLM07->LLM08  LLM08->LLM09  LLM09->LLM07  LLM10->LLM06

Renamed and re-scoped:
- LLM08 Hidden Context Exposure (was System Prompt Leakage) — widened from
  the system prompt to all non-user-facing context, including developer
  instructions, retrieved policy text, and tool and function schemas
- LLM10 Improper Output Handling (was Insecure Output Handling) — widened to
  cover insecure code generated by coding assistants at scale
- LLM04 Supply Chain (was Supply Chain Vulnerabilities)
- Scope notes added to LLM01 (cross-modal payloads), LLM04 (artifact
  provenance), and LLM05 (fine-tuning subversion)

Severity re-baselined for the three entries whose rank moved, with the basis
recorded in RATIONALE.md 4.5: LLM03 High->Critical, LLM06 Medium->High,
LLM07 Medium->High.

Also fixes three framework files that still carried entries from the 2023
list. LLM_DORA.md, LLM_FedRAMP.md, and LLM_SP800218A.md each held a stale
Model DoS entry shadowing Unbounded Consumption, and Training Data Poisoning
in place of Data and Model Poisoning; their quick-reference tables were keyed
to pre-2025 numbering. Each was remapped by entry name, the duplicate dropped,
and the entries they never had were authored: LLM10 for DORA and FedRAMP,
LLM02 for SP 800-218A. The same stale cross-references in the agentic and
DSGAI counterparts of those files were repaired the same way.

Verified: generate.js extracts 10/10 entries from all 23 LLM framework files;
validate.js reports the same 51 errors and 67 warnings as before the change
(all pre-existing); 12/12 package tests pass; tsc clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The badge grep extracted every digit run from
'mapping%20files-67-brightgreen', so BADGE became "20\n67" and the
comparison against the file total always failed. Anchor the capture on the
'-<count>-' segment so the '20' inside the URL-encoded '%20' is not picked up.

Pre-existing; unrelated to the 2026 migration, but it blocks this PR's gate.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@emmanuelgjr
emmanuelgjr merged commit 6a3b867 into main Aug 28, 2026
1 of 4 checks passed
@emmanuelgjr
emmanuelgjr deleted the update/llm-top10-2026 branch August 28, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant