Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

LLM SecRange: Open-Source Penetration Testing Playground for Large Language Models & Vulnerable Agents

Summary

LLM SecRange is a localized, hands-on LLM offensive security testing platform built with Flask. It features 8 Gandalf-style prompt injection CTF challenges, OWASP LLM Top 10 (2025) vulnerability labs, and a vulnerable ReAct bank agent with tool-abuse flaws (SQLi, path traversal, RCE, IDOR). It supports dynamic target model switching across DeepSeek, OpenRouter, and offline Ollama.

Why it matters

Offers security researchers and penetration testers an out-of-the-box, comprehensive environment to practice prompt injection, OWASP LLM Top 10 risks, and agent tool-abuse exploitation against real models.
Published
Collected

original ↗

Related coverage

back