Vibe-Coded Apps Riddled with Flaws: AI Dev Speeds Up Commits 3-4x, Security Alerts 10x
alex_verem · x · 2026-08-02
Escape scanned 5,600 public-facing apps built via "vibe coding" and found that 25% contained critical security flaws. The researchers identified 2,038 critical vulnerabilities, over 400 leaked secrets (including API keys), and 175 exposed PII records. The Cloud Security Alliance noted a complete lack of basic protections like CSRF or security headers across the entire sample.
A parallel study by Apiiro across Fortune 50 enterprises revealed that while AI-assisted developers pushed commits 3-4x faster, they also generated security findings 10x faster, causing monthly alerts to surge from roughly 1,000 to over 10,000 within six months.
More from coding & agent
- Switching structured output tasks to smaller models cuts costs by 96% — jxnlco · 2026-08-02
- Mastering Harnesses Like Codex Is the Best Investment for AI Agents — TheZachMueller · 2026-08-02
- Building a High-Quality AI Research Stack with Multi-Agent Verification Loops — EXM7777 · 2026-08-02
- From 10x Coder to Vibe Coder: The Identity Crisis of AI-Assisted Programming — facontidavide · 2026-08-02
- Open-Source LoRA Studio: Fully Automated Training from a Single Photo — Ill-Ant-9489 · 2026-08-02
- Claude Code Autonomy Flaws: Over-Reliance on grep Causes Spec Shortcuts — craigbalding · 2026-08-02