← Back to learn hub
LLM08

Vector & Embedding Weaknesses

RAG poisoning, indirect injection, EchoLeak cross-context leakage, Copilot image tag injection, embedding inversion

What is Vector & Embedding Weaknesses?

Vector & Embedding Weaknesses is ranked LLM08 in the OWASP LLM Top 10 (2025) — the industry-standard taxonomy for large language model security risks. It represents one of the most commonly exploited vulnerability classes in production AI deployments.

How Nemesis tests for it

Vector & Embedding Weaknesses

RAG poisoning via malicious document chunks, indirect injection via retrieval context, cross-document instruction bleed.

5 test casesNIST SI-7NIST CM-6NIST SA-11

Real-world incidents

2025 - Black Hat
GoogleGoogle Gemini

Demonstrated at Black Hat 2025, this attack showed that any data source that an LLM processes can serve as an injection vector. Calendar invites, emails, documents, and web pages - if the model reads it, an attacker can weaponise it.

Black Hat 2025

Test your model for Vector & Embedding Weaknesses

Run the full LLM08 attack suite against your LLM in minutes.

Run free scan →