Vulnerabilities

Vibe-Coded Apps Security Flaws

July 23, 2026 12:27 · 12 min read
Vibe-Coded Apps Security Flaws

Vibe Coding and Security Concerns

Vibe coding, the use of AI to assist or perform code generation, is on the rise, with 90% of developers regularly using at least one AI tool at work as of January 2026, according to Hostinger. However, this increase in vibe coding has also led to concerns over the security of vibe-developed apps.

Xint.io Study

Xint.io, a web platform that delivers Theori's AI-driven autonomous pentest code, conducted a study to analyze vibe-coded apps and quantify the security weaknesses introduced by vibe coding. The study created three tests reflecting common AI-assisted development workflows: a new app from a well-written spec, a new app representing the growing incidence of casual coders, and a hardened app to see if hardening introduced new vulnerabilities.

The study found a total of 434 exploitable security issues: 196 in the greenfield apps and 238 in the single brownfield app. The primary conclusions reached by Xint.io cover four areas: the most common flaws in AI code, the most common severe flaws, the effect of app size on flaws introduced, and whether AI has made advances in producing secure code.

Common Flaws in AI Code

Missing controls for rate limiting and DOS were the most common flaws, with resource exhaustion/DOS accounting for 93 of the 434 flaws. Authorization and insecure direct object reference were the second most common, with 88 flaws, and access boundary/traversal/SSRF flaws were third, with 54. These flaws occur when the developer only asks for features, which can lead to significant security issues.

Xint's advice is to look beyond just checking if AI code compiles and to examine how it performs and the resources it consumes in runtime. Secrets exposure is the top source of critical-severity flaws, with hardcoded or default secrets being the most common at 11. Debug-mode RCE accounted for another six.

Size Matters

The study found that fine-grained authorization holds up on small apps but breaks as the app grows. While IDOR flaws comprised just 11% of the flaws in the smaller greenfield apps, they comprised 28% in the larger brownfield Gnuboard7 app. Xint suggests double-checking granular object permissions as the amount of endpoints in an application increases.

Improving Vibe Coding AI

Despite the continuing flaws being introduced by vibe coding, Xint's fourth conclusion is that vibe coding AI is improving. The study expected to find a large number of injection flaws and IDOR/BOLA-style access-control bugs but found the opposite. This suggests that the foundational labs have genuinely improved in these areas.

The purpose of the Xint study was not to demonstrate that vibe coding introduces bugs, but to help developers overcome them by understanding the most common flaws and how and why they occur. By knowing the weaknesses in vibe coding, developers can play to its strengths in the future.

Related studies and articles have also highlighted the importance of security in vibe coding, including the need for secure coding practices and the potential risks of vibe coding. As the use of AI in development continues to grow, it is essential to prioritize security and ensure that vibe-coded apps are secure and reliable.

Conclusion

In conclusion, the Xint.io study highlights the need for improved security measures in AI-assisted development. The study's findings emphasize the importance of looking beyond just checking if AI code compiles and examining how it performs and the resources it consumes in runtime. By understanding the weaknesses in vibe coding, developers can play to its strengths and create more secure and reliable apps.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free