Vibe Coding Security: What Research and Incidents Show
AI-generated code passes security tests a little more than half the time, and the average has barely moved since Veracode began reporting it in 2025. Veracode's report of July 28, 2026 put the average security pass rate across models at 56%, against 55% in its first report. The documented incidents involve ordinary failures: databases without access rules, apps without login, keys shipped to the browser, and AI agents holding credentials they should not have.
Maintainability and the path to production are covered separately: Why vibe coding fails in production.
Is AI-generated code secure?
About half of it is, on tasks built to test security. Models do well on some vulnerability classes and badly on others, and the headline rate changed little between 2021 and 2026.
| Study | Published | What was tested | Result |
|---|---|---|---|
| Pearce et al., "Asleep at the Keyboard?" | August 20, 2021 (IEEE S&P 2022) | 1,689 programs from GitHub Copilot across 89 high-risk scenarios | "approximately 40%" vulnerable |
| Veracode GenAI Code Security Report | July 30, 2025 | Over 100 models in Java, Python, C# and JavaScript | 45% of samples failed; Java failed 72% |
| Veracode 2026 report | July 28, 2026 | Same benchmark, more models | 56% average pass rate; best model 68% |
| SusVibes, Zhao et al. | December 2, 2025; v4 September 21, 2026 | 186 feature requests from real open-source projects, 12 agent setups | SWE-Agent with Claude 4 Sonnet: 57% functionally correct, 11.8% secure |
| Tenzai, "Bad Vibes" | June 25, 2026 (tests run December 2025) | 15 apps built by Cursor, Claude Code, Codex, Replit and Devin | 69 vulnerabilities; none of the 15 apps had proper CSRF protection |
Veracode's update of March 24, 2026 put syntax correctness above 95% while security pass rates stayed near 55%.
The split by vulnerability class is the useful part. In Veracode's July 2026 data, models passed SQL injection tasks 83% of the time and cryptography tasks 87%, but "performance fell sharply on cross-site scripting at 15% and log injection at 12%."
Tenzai saw the same pattern in complete apps: "We didn't encounter a single exploitable SQLi or XSS vulnerability," but "Coding agents did very poorly in terms of properly enforcing authorization." Four of five agents accepted orders with a negative total, and every app had "a login page with zero rate limiting or account lockout mechanisms."
Models handle flaws with a standard local fix, such as parameterized queries. They miss flaws that depend on the application's own rules: who owns a record, whether a price can be negative.
Three cautions apply. These are failure rates on security-focused tasks, not on all AI-written code. SusVibes uses tasks where human programmers had also committed vulnerable code. Veracode and Tenzai sell security products.
Asking the model for secure code is not a dependable fix. The SusVibes authors found that "augmenting the feature request with vulnerability hints, cannot mitigate these security issues."
What does field data from deployed apps show?
Scans of live apps find the same few misconfigurations at scale.
Wiz Research wrote on September 18, 2025: "we discovered a pattern of common, high-impact misconfigurations and found that 1 in 5 organizations build on these platforms, inadvertently exposing themselves to risk." It named four: authentication handled entirely in the browser (including passwords hard-coded in JavaScript), API keys in client-side code, database tables open to anyone, and internal apps published without authentication.
Escape reported on October 29, 2025 that it "analyzed over 5,600 publicly available applications and identified more than 2,000 vulnerabilities, 400+ exposed secrets, and 175 instances of PII". The sample was mostly Lovable apps and the scan was passive, so Escape calls its counts lower-bound estimates.
WIRED reported on May 7, 2026 that RedAccess found more than 5,000 apps built with Lovable, Replit, Base44 and Netlify "that had virtually no security or authentication", and that around 40 percent exposed sensitive data. Replit's reply to WIRED: "Public apps being accessible on the internet is expected behavior."
Georgia Tech reported on April 13, 2026 on its Vibe Security Radar, which traces published vulnerabilities back to commits made with AI tools. "Of the 74 confirmed cases uncovered so far by the tool, 14 are critical risks, and 25 are high." The radar detects only tools that leave a signature in commits.
How often does AI-assisted code leak secrets?
Often enough to measure. GitGuardian's State of Secrets Sprawl 2026 report counted 28,649,024 new secrets in public GitHub commits during 2025, a 34% increase. It found that "Claude Code co-authored commits leak secrets at ~2× the baseline across all Public GitHub commits" and recorded "24,008 unique secrets exposed in MCP configuration files".
Of the secrets GitGuardian detected in 2022, "64% are still active and exploitable". Its post of April 9, 2026 reported 992% year-over-year growth in leaked Supabase credentials and summarized the cause: "When code production speeds up, insecure patterns scale with it." The data covers public GitHub only, and the 2× figure applies only to commits carrying a Claude Code co-author line.
What are hallucinated dependencies, and are they a real risk?
Models sometimes recommend packages that do not exist, and an attacker can register the invented name. The mechanism is documented, but we found no confirmed case of a named vibe-coded app compromised this way.
Spracklen et al., first posted June 12, 2024 and presented at USENIX Security 2025, generated 576,000 code samples with 16 models. Hallucinated packages averaged "at least 5.2% for commercial models and 21.7% for open-source models". Socket noted on April 8, 2025 that "43% of hallucinated packages were repeated every time" across ten runs. Repeatable names make the attack, called slopsquatting, practical.
Which vibe coding incidents are documented, and what caused each?
Six named cases are well sourced. Together with the scans above, their causes fall into four classes: missing authorization on the data layer, no authentication, an agent with credentials it should not have had, and a flaw in the builder platform. None needed an advanced exploit.
| Incident | Source and date | What happened | Root-cause class |
|---|---|---|---|
| Lovable, CVE-2025-48757 | Matt Palmer, May 29, 2025 | 303 endpoints across 170 of 1,645 scanned projects had inadequate row-level security | Missing data-layer authorization |
| Replit agent, SaaStr | The Register, July 21, 2025; Replit CEO, July 20, 2025 | Agent "deleted data from the production database"; data was restored | Agent credentials; no dev/prod separation |
| Base44 | Wiz, July 29, 2025 | A non-secret app_id was enough to create a verified account on private apps; fixed in under 24 hours, no evidence of abuse | Platform flaw |
| Moltbook | Wiz, February 2, 2026 | Full read and write access to the database; 1.5 million API tokens and 35,000 email addresses exposed | Missing data-layer authorization |
| Lovable platform | The Register, April 21, 2026 | A researcher with a free account reported reading other users' source code, credentials and chat histories | Platform flaw (broken object-level authorization) |
| PocketOS | The Register, April 27, 2026 | Coding agent deleted the production database and its volume-level backups in one API call; data was recovered | Over-scoped token in the repository; backups beside the data |
Two widely cited cases do not belong on this list. One was misattributed and one is disputed.
The Tea app breach is often blamed on vibe coding. 404 Media reported on July 25, 2025 that the data sat in an exposed Firebase storage bucket. Tea said the dataset dated "from prior to February 2024", and Simon Willison wrote on July 26, 2025, "I'm confident vibe coding was not to blame in this particular case".
On February 20, 2026, Amazon published a rebuttal to a Financial Times report that tied an AWS interruption to an AI coding tool. Amazon attributes the December event, which it says affected one service in one region, to "user error" and "misconfigured access controls". We could not open the paywalled FT article, so we treat the cause as contested.
Is Lovable secure?
Lovable has two documented problems of different kinds, and both kinds also appear on competing platforms. On any of them, the owner remains responsible for the app's own access rules.
The 2025 case concerned generated projects. Palmer wrote on May 29, 2025 that Lovable's security scanner "merely checks for the existence of any RLS policy, not its correctness or alignment with application logic." Palmer works at Replit, a competitor. Lovable told Semafor on May 29, 2025: "We're not yet where we want to be in terms of security and we're committed to keep improving the security posture for all Lovable users."
The 2026 case concerned the platform itself. According to The Register's report of April 21, 2026, Lovable first described visible code on public projects as "intentional behavior" and later wrote, "We understand that pointing to documentation issues alone was not enough here."
On any builder, test your own project's database rules (check 1 below).
How can you tell if code is AI generated?
You cannot tell reliably from the running app. A repository offers signals, such as co-author lines in commit messages and configuration files left by coding tools, but they are incomplete.
Researchers face the same limit. In Georgia Tech's April 13, 2026 release, researcher Hanqing Zhao said, "Claude Code and Copilot together account for most of what we detect, but that's partly because they leave the clearest signatures." CodeRabbit wrote on December 17, 2025 that "it was impossible to directly confirm authorship of each PR".
Authorship matters less than whether anyone reviewed and tested the code.
What security checklist can a founder run this week?
These nine checks cover the failure classes above. Most need only a browser and your own accounts. Run them only on apps you own.
| # | Check | How to run it | What it catches |
|---|---|---|---|
| 1 | Database rules | With the public key from your app's network requests, query each table while logged out. Private rows coming back mean row-level security is missing or too loose | Lovable CVE, Moltbook |
| 2 | Login on every page | Open every page and API route in a private window with no session | Wiz, RedAccess |
| 3 | Cross-user access | Sign in as user A and change record IDs in URLs and requests to user B's | Tenzai, Lovable platform |
| 4 | Keys in the browser | Search the built JavaScript for third-party keys and tokens | Wiz, Escape |
| 5 | Keys in the repository | Run a secret scanner over the git history and any agent or MCP config files. Rotate everything found | GitGuardian |
| 6 | Dependencies | Confirm each package exists and is the one intended. Run a vulnerability audit on the lockfile | Spracklen et al., Socket |
| 7 | Hostile input | Submit negative numbers, oversized text and script tags to every form and API | Tenzai, Veracode |
| 8 | Baseline controls | Check for login rate limiting, CSRF protection and security headers | Tenzai |
| 9 | Agent access | List every credential your coding agent can read. Separate development from production, narrow token scopes, keep backups elsewhere, test a restore | Replit, PocketOS |
On check 1, a visible public key is expected. Wiz's Moltbook report of February 2, 2026 explains: "When properly configured with Row Level Security (RLS), the public API key is safe to expose", but "without RLS policies, this key grants full database access to anyone who has it."
Key takeaways
- The average security pass rate for AI-generated code was 56% in Veracode's July 2026 report, against 55% in its first report.
- Models are strong on SQL injection and cryptography and weak on cross-site scripting, log injection and authorization.
- The well-sourced incidents trace to four causes: open data layer, no login, over-privileged agent, or platform flaw.
- Leaked keys persist: 64% of secrets found in 2022 were still valid.
- An owner can test for most of these failures without security tooling.
Frequently asked questions
Is AI-generated code secure?
Not by default. In Veracode's July 2026 benchmark the average security pass rate was 56%, and the best model reached 68%. Security depends on review and testing after generation.
What are the main vibe coding security risks?
Missing access rules on the database, missing or browser-only authentication, secrets in client code or the repository, and coding agents with production credentials. Field scans found the first three in deployed apps, and the Replit and PocketOS incidents show the fourth.
How do you secure a vibe-coded app?
Run the nine checks above, starting with database rules, login on every route, cross-user access and exposed keys. Rotate any key that has reached the browser or the repository, then separate development from production.
How can you tell a site or app is vibe coded?
Not reliably from outside. Commit metadata and tool configuration files in the repository are the usual signals, and researchers who depend on them say the signals are incomplete.
Easital audits and repairs vibe-coded applications, including the checks described here. See vibe-coding rescue and code audit services.
Sources
All sources were opened and checked on October 2, 2026.
- Veracode, "2026 GenAI Code Security Report: AI Is Writing More of Your Code but Security Hasn't Caught Up", July 28, 2026. https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/
- Veracode, "Spring 2026 GenAI Code Security Update", March 24, 2026. https://www.veracode.com/blog/spring-2026-genai-code-security/
- Veracode, "We Asked 100+ AI Models to Write Code. Here's How Many Failed Security Tests.", July 30, 2025. https://www.veracode.com/blog/genai-code-security-report/
- Pearce, Ahmad, Tan, Dolan-Gavitt, Karri, "Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code Contributions", arXiv 2108.09293, August 20, 2021 (IEEE S&P 2022). https://arxiv.org/abs/2108.09293
- Zhao, Wang, Zhang, Luo, Li, Li, "Is Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World Tasks", arXiv 2512.03262, December 2, 2025 (v4 September 21, 2026). https://arxiv.org/abs/2512.03262
- Tenzai, "Bad Vibes: Comparing the Secure Coding Capabilities of Popular Coding Agents", June 25, 2026. https://www.tenzai.com/blog/bad-vibes-comparing-the-secure-coding-capabilities-of-popular-coding-agents
- Wiz Research (Gal Nagli, Alon Schindel), report on common security risks in vibe-coded apps, September 18, 2025. https://www.wiz.io/blog/common-security-risks-in-vibe-coded-apps
- Escape, "Methodology: How we discovered over 2k high-impact vulnerabilities in apps built with vibe coding platforms", October 29, 2025. https://escape.tech/blog/methodology-how-we-discovered-vulnerabilities-apps-built-with-vibe-coding/
- WIRED, "Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web", May 7, 2026. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/
- Georgia Tech, "Bad Vibes: AI-Generated Code is Vulnerable, Researchers Warn", April 13, 2026. https://news.research.gatech.edu/2026/04/13/bad-vibes-ai-generated-code-vulnerable-researchers-warn
- GitGuardian, "The State of Secrets Sprawl 2026", 2026. https://www.gitguardian.com/state-of-secrets-sprawl-report-2026
- GitGuardian, "When We Use AI To Ship Fast, Secrets Spread Fast", April 9, 2026. https://blog.gitguardian.com/ai-secrets-spread-fast/
- Spracklen, Wijewickrama, Sakib, Maiti, Viswanath, Jadliwala, "We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs", arXiv 2406.10279, June 12, 2024 (USENIX Security 2025). https://arxiv.org/abs/2406.10279
- Socket, "The Rise of Slopsquatting", April 8, 2025. https://socket.dev/blog/slopsquatting-how-ai-hallucinations-are-fueling-a-new-class-of-supply-chain-attacks
- Matt Palmer, "Statement on CVE-2025-48757", May 29, 2025. https://mattpalmer.io/posts/statement-on-CVE-2025-48757/
- Semafor, "The hottest new vibe coding startup may be a sitting duck for hackers", May 29, 2025. https://www.semafor.com/article/05/29/2025/the-hottest-new-vibe-coding-startup-lovable-is-a-sitting-duck-for-hackers
- The Register, "Vibe coding service Replit deleted user's production database, faked data, told fibs galore", July 21, 2025. https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/
- Amjad Masad, post on X, July 20, 2025. https://x.com/amasad/status/1946986468586721478
- Wiz, "Wiz Research Uncovers Critical Vulnerability in AI Vibe Coding platform Base44 Allowing Unauthorized Access to Private Applications", July 29, 2025. https://www.wiz.io/blog/critical-vulnerability-base44
- Wiz, "Hacking Moltbook: The AI Social Network Any Human Can Control", February 2, 2026. https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys
- The Register, "Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus", April 21, 2026. https://www.theregister.com/security/2026/04/21/lovable-denies-data-leak-cites-intentional-behavior/5226233
- The Register, "Cursor-Opus agent snuffs out startup's production database", April 27, 2026. https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/5224442
- 404 Media, "Women Dating Safety App 'Tea' Breached, Users' IDs Posted to 4chan", July 25, 2025. https://www.404media.co/women-dating-safety-app-tea-breached-users-ids-posted-to-4chan/
- Simon Willison, "Official statement from Tea on their data leak", July 26, 2025. https://simonwillison.net/2025/Jul/26/official-statement-from-tea/
- Amazon, "AI coding bot didn't take down AWS, Amazon confirms", February 20, 2026. https://www.aboutamazon.com/news/aws/aws-service-outage-ai-bot-kiro
- CodeRabbit, "Our new report: AI code creates 1.7x more problems" (State of AI vs Human Code Generation Report), December 17, 2025. https://www.coderabbit.ai/blog/state-of-ai-vs-human-code-generation-report

