-
Notifications
You must be signed in to change notification settings - Fork 4.5k
New CS proposal: RAG Security #2126
Copy link
Copy link
Open
Labels
ACK_OBTAINEDIssue acknowledged from core team so work can be done to fix it.Issue acknowledged from core team so work can be done to fix it.NEW_CSIssue about the creation of a new cheat sheet.Issue about the creation of a new cheat sheet.
Metadata
Metadata
Assignees
Labels
ACK_OBTAINEDIssue acknowledged from core team so work can be done to fix it.Issue acknowledged from core team so work can be done to fix it.NEW_CSIssue about the creation of a new cheat sheet.Issue about the creation of a new cheat sheet.
Type
Fields
Give feedbackNo fields configured for issues without a type.
Retrieval Augmented Generation is now standard architecture for enterprise AI applications, but no OWASP cheat sheet covers its unique attack surface. AISVS addresses RAG in C08 (Memory, Embeddings and Vector Database) but there is no practitioner-level guidance on how to defend RAG pipelines in production.
This cheat sheet would cover:
References: OWASP AISVS C08, OWASP Top 10 for LLM Applications, OWASP AI Exchange.
Happy to contribute to or co-author the draft.
Thanks,
Raza