Two new studies found that AI-generated application code frequently contains exploitable vulnerabilities, with risk varying sharply by model, framework, and application size. Secure Code Warrior said testing of 1,760 complete codebases produced by 16 frontier models uncovered more than 27,000 vulnerabilities, averaging 15 confirmed flaws per codebase and 4.3 critical or high-severity issues. Researchers said no single model was consistently safest across all environments; instead, each model showed a repeatable security fingerprint, with recurring OWASP weakness patterns and common omissions such as authentication checks and input validation.
Xint.io separately identified 434 exploitable flaws in AI-generated or AI-hardened applications, reporting that denial-of-service and resource exhaustion bugs, authorization failures, insecure direct object reference, and traversal or SSRF issues were common. The most severe findings were tied to hardcoded or default secrets and debug-mode remote code execution, while authorization weaknesses worsened as application size increased, particularly in a larger brownfield Gnuboard7-based app. Both reports said organizations should expect continued AI-assisted development and strengthen security review around recurring weaknesses such as hard-coded credentials, sensitive data leakage into logs, cross-site scripting, predictable session tokens or reset codes, and path traversal.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
An academic study from Beacom College of Computer & Cyber Sciences found exploitable vulnerabilities in every automation script generated by ChatGPT, Microsoft Copilot, and Google Gemini for web scraping, email automation, and file workflow tasks. Researchers identified 45 findings across nine Python scripts, collapsing them into 17 distinct vulnerability classes including SSRF, path traversal, email injection, symlink issues, and overly broad exception handling.
Xint.io analyzed AI-generated or AI-hardened applications and found 434 exploitable security flaws across the tested apps. The study highlighted denial-of-service, authorization, IDOR, traversal, SSRF, hardcoded secrets, and debug-mode remote code execution as major issues, while noting some improvement in certain injection and access-control bug classes.
Secure Code Warrior tested 1,760 complete codebases generated by 16 frontier models and found more than 27,000 vulnerabilities overall, averaging 15 confirmed vulnerabilities per codebase. The report concluded that security outcomes varied significantly by model-framework pairing and that models showed repeatable security fingerprints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.