Concerns about AI-generated code introducing massive security holes. Research found thousands of vibe-coded apps with exposed data, though debate exists whether these represent true vulnerabilities versus poor app design.
← Back to AI is breaking two vulnerability cultures
The debate over "vibe coding" centers on whether AI is actively introducing new security risks or if its "slop" simply makes vulnerabilities easier to discover by creating a larger target. While researchers have identified thousands of AI-generated applications exposing sensitive medical and financial data due to a total lack of authentication, some argue these cases reflect poor individual design choices rather than systemic flaws in the AI tools themselves. This influx of AI-assisted code is reportedly overwhelming manual review processes, yet critics note that many high-impact vulnerabilities still stem from legacy logic errors that predate the AI era. Ultimately, the consensus suggests that while mature projects remain relatively stable, the sheer volume of low-effort, vibe-coded apps is creating a massive and poorly-secured new surface area for potential exploitation.
10 comments tagged with this topic