Peachy Cloud Security logo

    How an AI-Coded App Can Get Hacked

    Download the full checklist for securing AI-coded apps

    10 Anti-Patterns
    Real CVEs & Incidents
    40+ Security Checks
    Test Commands & Fixes
    Get Full Checklist

    Scroll down to preview the top 10 vibe coding anti-patterns

    Free Preview

    Vibe Coding Anti-Patterns: How AI Writes Vulnerable Code

    AI coding tools ship features fast, and they ship vulnerabilities just as fast. 87% of AI-generated pull requests contain at least one vulnerability. A scan of 1,400 vibe-coded apps found 2,038 critical vulnerabilities. And 45% of AI-generated code fails OWASP Top 10 security tests.

    This page walks through the 10 most dangerous vibe coding security anti-patterns, with real incidents, real CVEs and the exact code patterns to look for.

    This page covers the top 10 anti-patterns. The full checklist has 10 categories and 40+ individual checks, each with a severity rating, a test command and a plain-language fix. Download the complete checklist.

    Sources: DryRun Security 2026, Escape.tech Oct 2025, Veracode 2025

    1. Database Exposed to the Internet

    The Supabase key sits in client JavaScript. Row-level security (RLS) is never enabled on the SQL migrations. Anyone with a browser can query every table.

    curl "https://ref.supabase.co/rest/v1/users?select=*" \
      -H "apikey: anon-key-from-bundle"
    
    • CVE-2025-48757 (CVSS 9.3): Lovable apps allowed unauthenticated read and write to arbitrary tables.
    • Moltbook, January 2026: Supabase RLS was off. ~1.5M API tokens and 35K+ emails exposed, ~4.75M records enumerable. Patched in about 3 hours.

    Sources: NVD CVE-2025-48757, Wiz Research Jan 2026, Escape.tech Oct 2025

    2. Auth Lives Only in the Frontend

    AI agents put access control where they can see it: in the React route. The route hides the page, but the API endpoint behind it stays wide open. Call it directly and no session is needed.

    <Route path="/admin">
      {isAdmin ? <AdminPanel /> : <Redirect />}
    </Route>
    
    • Base44, July 2025: anyone with an app's public app_id could register on private and SSO-protected enterprise apps through two unauthenticated endpoints. Fixed within 24 hours.
    • 87% of AI-generated PRs had at least one vulnerability (143 issues across just 30 PRs), and broken access control was the top pattern.

    Sources: DryRun Security 2026, Wiz Research Jul 2025

    3. The Guessable Secret

    The string "supersecretkey" appeared as a hardcoded secret in 1,182 of 20,000 generated apps. Models reuse secrets from their training data; GPT-5's favourite was "supersecretjwt".

    const secret = process.env.JWT_SECRET || "dev-secret";
    

    The env var is not set in production, so the fallback ships. An attacker forges admin tokens. Impact: complete authentication bypass.

    Source: Invicti Security Labs, Nov 2025

    4. One ID Away From Everyone's Data

    Change the ID in the URL and get someone else's records. No ownership check, no tenant filter. It is the most common serious flaw in AI-generated apps.

    app.get("/api/invoice/:id", (req, res) => {
      db.findById(req.params.id); // no ownership check
    });
    
    • IDOR: the app never checks if the record belongs to you.
    • BOLA: a list endpoint returns every tenant's rows.
    • Mass assignment: send "role": "admin" in a profile update and the server saves it.

    Sources: DryRun Security 2026, CSA Vibe Coding Security Crisis 2025

    5. The Default Admin Is Still Live

    AI generates setup scripts with default credentials so the app works at once. The test account is never removed, and debug routes built during development stay deployed.

    Default credentials that ship: admin@admin.com / admin123, test@test.com / password, admin / admin

    Pages left open with no auth: /admin, /debug, /internal, /swagger, /actuator, /graphql

    • Debug mode leaks secrets: production error pages show environment variables, file paths, database queries and stack traces.
    • Version banners exposed: Server and X-Powered-By headers tell attackers your exact framework and version.

    Sources: CSA Vibe Coding Security Crisis 2025, OWASP Security Misconfiguration

    6. Phantom Packages (Slopsquatting)

    AI invents package names that don't exist. Attackers register them first. You install malware. This attack class exists only because of AI code generation.

    • 19.7% of generated code samples cite packages that don't exist.
    • 43% of hallucinated names came back in all 10 reruns, so they are predictable.

    The attack chain:

    1. AI hallucinates a package name.
    2. The name recurs predictably across reruns.
    3. An attacker pre-registers that exact name.
    4. Malware ships under a trusted-looking name.

    Source: "We Have a Package for You!", USENIX Security 2025 (2.23M samples, 16 models)

    7. The Agent That Deletes Production

    Replit, July 2025: an AI agent deleted a production database during a code freeze, wiping records for 1,200+ executives and 1,196 companies. Then the agent fabricated data about what happened.

    • Root cause: the agent held live production database credentials.
    • No rollback: platform version history does not restore database data.
    • CVE-2025-54135 (CurXecute): prompt injection chained into a config rewrite and code execution in Cursor below 1.3.9.

    Sources: The Register Jul 2025, AI Incident Database #1152, Pillar Security GHSA-4cxx-hrm3-49rm

    8. 28 Million Secrets Committed

    • Claude Code-assisted commits leak secrets at 3.2%, against a 1.5% baseline: more than double.
    • 28.65M new hardcoded secrets landed on public GitHub in 2025, up 34% year over year.
    • 1.27M AI-service credential leaks in 2025, up 81% year over year.

    Source: GitGuardian State of Secrets Sprawl 2026

    9. XSS in 86% of Samples

    Veracode tested 100+ LLMs and found an 86% XSS defense failure rate. Newer, larger models do not generate more secure code; the security gain is flat regardless of model size.

    dangerouslySetInnerHTML
    element.innerHTML = input
    template |safe
    v-html="userContent"
    

    Validation lives at the form level. Call the API directly and it accepts anything: no Zod, no Pydantic, no server-side check. That opens SQL injection, command injection and path traversal.

    Source: Veracode 2025 GenAI Code Security Report

    10. Security Regression

    1. Prompt 1, "Add authentication": the AI adds auth middleware, rate limiting and CSRF tokens correctly.
    2. Prompt 2, "Fix this error": the AI removes the RLS policy, drops validation and loosens CORS to clear a runtime error.
    3. Result: security is silently undone.

    15 of 15 production AI-built apps tested had no CSRF protection. Zero had it. The first prompt adds security; every feature prompt after it adds tables, routes and endpoints with none.

    Source: Tenzai, Dec 2025 (15 apps built by Cursor, Claude Code, Codex, Replit and Devin)

    You're still missing critical security issues

    This page covers 10 anti-patterns. The full checklist has 10 categories with 40+ individual checks, each with:

    • Severity rating (Critical / High / Medium)
    • Specific test command you can run right now
    • Plain-language fix with code examples
    • Real CVEs and incident references
    • Webhook forgery, PCI scope, SSRF, CORS, session hijacking, and 30+ more

    Know all the issues before your app gets hacked.

    You will be redirected to topmate.io to complete your purchase.

    Download Full Checklist

    Where AI, AppSec and cloud security meet hands-on labs.

    Support Our Work

    Subscribe, like, and share our videos.

    No Spam. Only updates.