Researchers examined 9,041 open-source applications built with Claude Code and Lovable, plus 200 publicly deployed applications, and identified 1,186 vulnerabilities. Their audit found that 91% of deployed applications had at least one flaw and that 65.77% of identified issues were Critical or High severity, led by broken access control, injection vulnerabilities, and authentication failures. The study attributes recurring defects to eight failure modes involving AI-agent memory, objectives, and knowledge; stronger prompts and agent harnesses reduced, but did not eliminate, exposure.
The findings align with reported failures in AI-generated applications, including CVE-2025-48757 (CVSS 9.3), where Lovable applications using Supabase could expose database tables without authentication when Row Level Security policies were absent. Organizations adopting AI coding agents should enforce human security review, automated application testing, secret scanning, least-privilege authorization, and explicit database access controls before deployment; they should also treat coding assistants and their dependencies as potential supply-chain and prompt-injection targets.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
The cited version of “Understanding the (In)Security of Vibe-Coded Applications” was revised. The paper identifies broken access control, injection, and authentication failures as leading issue categories and attributes recurring weaknesses to AI-agent memory, objective, and knowledge defects.
Junquan Deng, Zhiyu Fan, and Ruijie Meng submitted a study of 9,041 open-source Claude Code and Lovable applications and an audit of 200 publicly deployed applications. The audit identified 1,186 vulnerabilities; 91.0% of audited applications had at least one vulnerability, and 65.77% of identified flaws were Critical or High severity.
A Veracode update reported in March 2026 found that the pass rate for AI-generated code remained around 55% despite improvements in code compilability.
Attacks or vulnerabilities affecting Amazon Q Developer, Cursor, and GitHub Copilot were disclosed in 2025. Reported scenarios included a misconfigured GitHub token used to inject code into an Amazon Q Developer VS Code extension, MCP prompt-injection and configuration-poisoning attacks against Cursor, and hidden Unicode instructions in Copilot and Cursor rule files.
CVE-2025-48757 documented insufficient Row Level Security policies in Lovable-generated applications using Supabase, enabling unauthenticated attackers to read and write arbitrary affected tables. The issue was rated CVSS 9.3 and categorized as CWE-863 Incorrect Authorization; Lovable disputed the classification, saying RLS configuration is the customer's responsibility.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.