S0109RS3-T06-S0109-Z · Full risk code

Conversation Content Leaking Across Users

對話內容跨使用者外洩

Operation & Monitoring
Risk Description

When an enterprise knowledge question-answering system has inadequate permission isolation, and confidential content from one department appears in another department's query results; due to unmitigated control gaps, on discovery the organization must review access controls comprehensively, triggering external stakeholder impacts and causing the system is suspended in the interim, and the leaked content cannot be recovered.

Framework Mappings

OWASP Top 10 for LLMLLM02
NIST AI 600-1Information Security
MITRE ATLASAML.T0024
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Enforce permission controls consistent with source systems across the retrieval-generation chain, filtering results by user entitlement; Strictly isolate conversation context and sessions, preventing residual context across users and departments; Verify isolation with cross-permission testing before launch and continuously audit access logs