LLM-powered applications reintroduce XSS vulnerabilities through insecure output handling (OWASP LLM05). When model output is inserted into the DOM without encoding, attackers can craft prompts that cause the LLM to generate malicious HTML or script tags, bypassing input sanitization. Two attack scenarios are covered: reflected
Table of contents
The Vulnerable FlowDetecting the IssueFrom Model Output to ExploitationGet Irem Bezci ’s stories in your inboxSort: