AI coding tools ship features fast, and they ship vulnerabilities just as fast. 87% of AI-generated pull requests contain at least one vulnerability. A scan of 1,400 vibe-coded apps found 2,038 critical vulnerabilities. And 45% of AI-generated code fails OWASP Top 10 security tests.
This page walks through the 10 most dangerous vibe coding security anti-patterns, with real incidents, real CVEs and the exact code patterns to look for.
This page covers the top 10 anti-patterns. The full checklist has 10 categories and 40+ individual checks, each with a severity rating, a test command and a plain-language fix. Download the complete checklist.
Sources: DryRun Security 2026, Escape.tech Oct 2025, Veracode 2025
1. Database Exposed to the Internet
The Supabase key sits in client JavaScript. Row-level security (RLS) is never enabled on the SQL migrations. Anyone with a browser can query every table.
curl "https://ref.supabase.co/rest/v1/users?select=*" \
-H "apikey: anon-key-from-bundle"
- CVE-2025-48757 (CVSS 9.3): Lovable apps allowed unauthenticated read and write to arbitrary tables.
- Moltbook, January 2026: Supabase RLS was off. ~1.5M API tokens and 35K+ emails exposed, ~4.75M records enumerable. Patched in about 3 hours.
Sources: NVD CVE-2025-48757, Wiz Research Jan 2026, Escape.tech Oct 2025
2. Auth Lives Only in the Frontend
AI agents put access control where they can see it: in the React route. The route hides the page, but the API endpoint behind it stays wide open. Call it directly and no session is needed.
<Route path="/admin">
{isAdmin ? <AdminPanel /> : <Redirect />}
</Route>
- Base44, July 2025: anyone with an app's public
app_idcould register on private and SSO-protected enterprise apps through two unauthenticated endpoints. Fixed within 24 hours. - 87% of AI-generated PRs had at least one vulnerability (143 issues across just 30 PRs), and broken access control was the top pattern.
Sources: DryRun Security 2026, Wiz Research Jul 2025
3. The Guessable Secret
The string "supersecretkey" appeared as a hardcoded secret in 1,182 of 20,000 generated apps. Models reuse secrets from their training data; GPT-5's favourite was "supersecretjwt".
const secret = process.env.JWT_SECRET || "dev-secret";
The env var is not set in production, so the fallback ships. An attacker forges admin tokens. Impact: complete authentication bypass.
Source: Invicti Security Labs, Nov 2025
4. One ID Away From Everyone's Data
Change the ID in the URL and get someone else's records. No ownership check, no tenant filter. It is the most common serious flaw in AI-generated apps.
app.get("/api/invoice/:id", (req, res) => {
db.findById(req.params.id); // no ownership check
});
- IDOR: the app never checks if the record belongs to you.
- BOLA: a list endpoint returns every tenant's rows.
- Mass assignment: send
"role": "admin"in a profile update and the server saves it.
Sources: DryRun Security 2026, CSA Vibe Coding Security Crisis 2025
5. The Default Admin Is Still Live
AI generates setup scripts with default credentials so the app works at once. The test account is never removed, and debug routes built during development stay deployed.
Default credentials that ship: admin@admin.com / admin123, test@test.com / password, admin / admin
Pages left open with no auth: /admin, /debug, /internal, /swagger, /actuator, /graphql
- Debug mode leaks secrets: production error pages show environment variables, file paths, database queries and stack traces.
- Version banners exposed:
ServerandX-Powered-Byheaders tell attackers your exact framework and version.
Sources: CSA Vibe Coding Security Crisis 2025, OWASP Security Misconfiguration
6. Phantom Packages (Slopsquatting)
AI invents package names that don't exist. Attackers register them first. You install malware. This attack class exists only because of AI code generation.
- 19.7% of generated code samples cite packages that don't exist.
- 43% of hallucinated names came back in all 10 reruns, so they are predictable.
The attack chain:
- AI hallucinates a package name.
- The name recurs predictably across reruns.
- An attacker pre-registers that exact name.
- Malware ships under a trusted-looking name.
Source: "We Have a Package for You!", USENIX Security 2025 (2.23M samples, 16 models)
7. The Agent That Deletes Production
Replit, July 2025: an AI agent deleted a production database during a code freeze, wiping records for 1,200+ executives and 1,196 companies. Then the agent fabricated data about what happened.
- Root cause: the agent held live production database credentials.
- No rollback: platform version history does not restore database data.
- CVE-2025-54135 (CurXecute): prompt injection chained into a config rewrite and code execution in Cursor below 1.3.9.
Sources: The Register Jul 2025, AI Incident Database #1152, Pillar Security GHSA-4cxx-hrm3-49rm
8. 28 Million Secrets Committed
- Claude Code-assisted commits leak secrets at 3.2%, against a 1.5% baseline: more than double.
- 28.65M new hardcoded secrets landed on public GitHub in 2025, up 34% year over year.
- 1.27M AI-service credential leaks in 2025, up 81% year over year.
Source: GitGuardian State of Secrets Sprawl 2026
9. XSS in 86% of Samples
Veracode tested 100+ LLMs and found an 86% XSS defense failure rate. Newer, larger models do not generate more secure code; the security gain is flat regardless of model size.
dangerouslySetInnerHTML
element.innerHTML = input
template |safe
v-html="userContent"
Validation lives at the form level. Call the API directly and it accepts anything: no Zod, no Pydantic, no server-side check. That opens SQL injection, command injection and path traversal.
Source: Veracode 2025 GenAI Code Security Report
10. Security Regression
- Prompt 1, "Add authentication": the AI adds auth middleware, rate limiting and CSRF tokens correctly.
- Prompt 2, "Fix this error": the AI removes the RLS policy, drops validation and loosens CORS to clear a runtime error.
- Result: security is silently undone.
15 of 15 production AI-built apps tested had no CSRF protection. Zero had it. The first prompt adds security; every feature prompt after it adds tables, routes and endpoints with none.
Source: Tenzai, Dec 2025 (15 apps built by Cursor, Claude Code, Codex, Replit and Devin)

