OWASP leaders warn prompt injection's low incident ranking hides its real danger
Prompt injection has topped the OWASP Top 10 for LLM applications for three straight years, yet it appears only 12th when measured against 6,639 labeled real-world incidents. The discrepancy stems from the attack's invisibility to vulnerability scanners, not a lower threat level. The finding comes from Kyriakos Lambros and Steve Wilson, co-leaders of the OWASP project, in a paper posted on arXiv.
The OWASP Top 10 for LLM applications has ranked prompt injection as its top risk for three consecutive years, yet a new analysis of 6,639 labeled real-world incidents places it only 12th. The authors, Kyriakos Lambros and Steve Wilson, argue this gap reflects a measurement blind spot: vulnerability scanners rarely detect prompt injection, so it remains underreported in incident data. The paper, posted on arXiv, suggests the attack’s true prevalence is likely far higher than current tallies show.
This discrepancy matters because rankings often guide security budgets and tooling priorities. If scanners miss prompt injection, organizations may underestimate their exposure while focusing on more visible threats. The OWASP project’s leadership emphasizes that the attack’s low incident count does not equal low danger—it simply means the threat is harder to observe in practice.
This finding could reshape how enterprises assess AI security, prompting a shift from scanner-based metrics toward more manual or behavioral testing. Organizations relying on automated vulnerability reports may be falsely reassured, while those adopting LLMs in sensitive roles—customer service, code generation, or data processing—could face unnoticed manipulation. Regulators and auditors may also need to reconsider compliance frameworks that depend on incident counts. The broader impact is a call for more realistic threat modeling, though the paper’s influence depends on how quickly tool vendors and security teams adapt their detection methods.