Back to feed
Dev.to
Dev.to
7/13/2026
AI-generated code contains significant security vulnerabilities, studies show 87% of PRs affected

AI-generated code contains significant security vulnerabilities, studies show 87% of PRs affected

Original: The Vibe Coding Hangover, Part 2: Your AI Didn't Just Write Bugs, It Wrote Backdoors

Short summary

AI coding agents are introducing serious security vulnerabilities into production code at alarming rates. DryRun Security found 87% of AI-generated PRs contained at least one vulnerability, and Veracode reports 45% of AI code samples have OWASP Top 10 issues. Common patterns include broken access control, leaked secrets, hallucinated malicious dependencies (slopsquatting), and unsupervised agent sprawl. The root cause is that models were never trained to think like attackers.

  • 87% of AI-generated PRs in a DryRun Security study had at least one vulnerability
  • Common AI code security failures: broken access control, leaked secrets, slopsquatting via hallucinated packages
  • 35 CVEs tied to AI coding tools logged in March 2026 alone, with real numbers estimated 5-10x higher

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more