Vibe-Coded Apps Riddled with Flaws: AI Dev Speeds Up Commits 3-4x, Security Alerts 10x

alex_verem · x · 2026-08-02

Escape scanned 5,600 public-facing apps built via "vibe coding" and found that 25% contained critical security flaws. The researchers identified 2,038 critical vulnerabilities, over 400 leaked secrets (including API keys), and 175 exposed PII records. The Cloud Security Alliance noted a complete lack of basic protections like CSRF or security headers across the entire sample.

A parallel study by Apiiro across Fortune 50 enterprises revealed that while AI-assisted developers pushed commits 3-4x faster, they also generated security findings 10x faster, causing monthly alerts to surge from roughly 1,000 to over 10,000 within six months.

Original post →

More from coding & agent

coding & agent channel →