LLM07:2025: System Prompt Leakage
System prompt contents (instructions, persona, embedded credentials/keys, or operational logic) extracted by an attacker via probing or prompt injection.
How it's found
Identified through repeat-back and role-confusion prompts that test whether system instructions, embedded credentials, or tool lists are recoverable.
Standards mapping
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Exposure of Sensitive Information to an Unauthorized Actor using Vuln Scanner's exposure templates (exposed configuration files, admin panels, API keys, .env and .git paths), with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness. For AI/LLM targets, Paladin AI additionally probes model responses for sensitive-information disclosure, such as leaked system prompts, training-data fragments, or credentials surfaced in generated output.
Tools: Vuln Scanner, Paladin AI
Frequently asked questions
What is LLM07:2025 System Prompt Leakage?
System prompt contents (instructions, persona, embedded credentials/keys, or operational logic) extracted by an attacker via probing or prompt injection.
How do you find System Prompt Leakage?
Identified through repeat-back and role-confusion prompts that test whether system instructions, embedded credentials, or tool lists are recoverable.
Which CWEs map to LLM07:2025?
LLM07:2025 maps to CWE-200, CWE-668.
Does TurboPentest test for System Prompt Leakage?
TurboPentest's automated black-box pentest actively probes for Exposure of Sensitive Information to an Unauthorized Actor using Vuln Scanner's exposure templates (exposed configuration files, admin panels, API keys, .env and .git paths), with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness. For AI/LLM targets, Paladin AI additionally probes model responses for sensitive-information disclosure, such as leaked system prompts, training-data fragments, or credentials surfaced in generated output.
Related OWASP categories
- OWASP Top 10 for LLM ApplicationsLLM01:2025: Prompt Injection
- OWASP Top 10 for LLM ApplicationsLLM02:2025: Sensitive Information Disclosure
- OWASP Top 10 for LLM ApplicationsLLM03:2025: Supply Chain
- OWASP Top 10 for LLM ApplicationsLLM04:2025: Data and Model Poisoning
- OWASP Top 10 for LLM ApplicationsLLM05:2025: Improper Output Handling
- OWASP Top 10 for LLM ApplicationsLLM06:2025: Excessive Agency
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest