QuestionQ7

AI-assisted security

A security analyst observes that, irrespective of user-submitted prompts, an AI model consistently produces unsanitized responses. Those responses are subsequently passed to multiple plug-ins. The analyst is concerned about the potential security effects of unsanitized input on those applications. Which of the following Open Worldwide Application Security Project (OWASP) categories covers this vulnerability?

Explanation

Improper output handling occurs when an LLM’s output is not adequately validated or sanitized before being passed to downstream systems such as plug-ins. This can allow untrusted model-generated content to trigger attacks against those systems, including code execution or other injection-related impacts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!