What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

Improper output handling

Improper output handling is the vulnerability of passing a large language model's output to another component, such as a browser, database, shell or file system, without validating, sanitizing or encoding it first. Because anyone who shapes the prompt shapes the output, the flaw hands attackers familiar exploits such as cross-site scripting, SQL injection and remote code execution.

Last reviewed

Key points

  • Improper output handling is trusting what a model writes. The output goes straight into a browser, a database query, a shell or a file path, and that system acts on it.
  • Whoever shapes the prompt shapes the output, so an attacker can reach those systems through the model, including by planting instructions in content the model reads.
  • The results are ordinary web exploits arriving by a new route, such as cross-site scripting, SQL injection, server-side request forgery and remote code execution.
  • OWASP's fix is to treat the model as any other user, encode output for where it lands, and use parameterized queries. It ranked the risk LLM05 in 2025 and LLM10 in 2026.

Improper output handling is what happens when an application treats a language model’s answer as safe and hands it to something that acts on it: a browser renders it, a database runs it, a shell executes it.

How it works

The model’s output is shaped by its input. OWASP says this is “similar to providing users indirect access to additional functionality”.

The attacker does not need direct access. Indirect prompt injection plants instructions in a web page, email or file the model later reads, and the model writes the payload.

What the payload does depends on where the output lands. OWASP’s examples:

  • Browser. Model-written JavaScript or Markdown is interpreted by the user’s browser: cross-site scripting (XSS).
  • Database. Model-written SQL runs without parameterization, which passes values separately from the query so they cannot change it: SQL injection.
  • Shell or eval. Output run as a command or code: remote code execution.
  • File system. Output used to build a file path can reach files outside the intended folder.

OWASP says a model granted more privilege than the end user raises the impact, enabling privilege escalation or remote code execution. Granting that excess is excessive agency.

Why it matters

Improper output handling brings decades-old web vulnerabilities back through a new door. In OWASP’s simplest scenario, a user asks a chat feature for a query that deletes every table. If nobody checks the query, the tables are gone.

The fixes are the old ones too. OWASP’s first is to “Treat the model as any other user, adopting a zero-trust approach”. Then encode output for where it will be used, use parameterized queries for every database operation involving model output, and apply a strict Content Security Policy, a browser rule that limits which scripts a page may run.

MITRE ATLAS adds structured output validation, one of the guardrails it lists: check schemas, types and allowed values “before model outputs are consumed by downstream systems”.

In practice

A Markdown image can leak data without any code running. In 2024 Johann Rehberger showed that GitHub Copilot Chat in VS Code rendered images in the model’s replies. Instructions hidden in a source file told the model to write an image link with chat data in its URL. Rendering the image sent that data to the attacker’s server. He reported it in February 2024. The fix, confirmed that June, appears to be that Copilot Chat stopped rendering Markdown images.

OWASP’s 2026 entry describes the same pattern. It asks client renderers to stop auto-loading Markdown images, link previews and iframes by default, or to allow only listed origins.

How the entry has changed

The definition has stayed the same while the entry’s rank and scope moved.

  • v1.1 (2023/24): LLM02, named Insecure Output Handling.
  • 2025: LLM05, renamed Improper Output Handling.
  • 2026: LLM10. OWASP’s preface says it “fell the furthest, from fifth to tenth”, while also noting that it “now spans the insecure code that assistants generate at scale.”

The 2026 entry also adds two sinks the 2025 one did not name. The first is terminals, logs and IDEs that interpret control characters such as ANSI escape sequences, hidden codes that change what a terminal shows or does. The second is renderers that fetch external resources on their own. It also draws a sharper boundary. Validating what goes into the model belongs to prompt injection. Wrong or misleading output belongs to misinformation. Improper output handling covers unsafe use of the output downstream. For how output validation compares with input filtering, see input filtering vs output validation.

Questions and answers

What is improper output handling in LLM applications?

Improper output handling is passing a language model's output to another system, such as a browser, database, shell or file path, without validating, sanitizing or encoding it first. OWASP lists it as LLM05 in its 2025 Top 10 for LLM Applications and as LLM10 in the 2026 edition.

How is improper output handling different from prompt injection?

Prompt injection is how an attacker changes what the model writes. Improper output handling is what lets that writing do damage: the application hands the output to a system that runs or interprets it. OWASP's 2026 entry says validating model inputs belongs to its prompt injection entry, and output handling covers what happens after the model responds.

How do you prevent improper output handling?

Treat the model as any other untrusted user. OWASP recommends validating model output before it reaches backend functions, encoding it for the place it will be used, using parameterized queries for any database operation involving it, and applying a strict Content Security Policy. The 2026 entry adds stripping terminal control characters and not auto-rendering Markdown images or link previews by default.

Is improper output handling the same as insecure output handling?

Yes. OWASP called the entry Insecure Output Handling (LLM02) in version 1.1 of its LLM Top 10 and renamed it Improper Output Handling in 2025, with the same opening definition.

Sources

  1. LLM05:2025 Improper Output HandlingOWASP GenAI Security Project
  2. LLM10:2026 Improper Output HandlingOWASP GenAI Security Project, 4 Aug 2026
  3. OWASP Top 10 for LLM Applications 2026, PrefaceOWASP GenAI Security Project, 4 Aug 2026
  4. LLM02: Insecure Output Handling (v1.1)OWASP
  5. MITRE ATLAS, AML.M0020 Generative AI Guardrails (collection 2026.09)MITRE
  6. GitHub Copilot Chat: From Prompt Injection to Data ExfiltrationEmbrace The Red (Johann Rehberger), 14 Jun 2024

Guides that use this term