Research Finds 60–65% of AI-Generated "Vibe Code" Is Vulnerable

A study found the majority of code written by AI assistants contains security vulnerabilities, with prompt injection being the top threat in deployed LLM systems. The findings challenge the growing "just vibe code it" trend.

Research Finds 60–65% of AI-Generated "Vibe Code" Is Vulnerable

A new security study is putting hard numbers on a problem many engineers have seen firsthand: AI-generated code often looks finished before it is actually safe. According to the research highlighted in recent AI news coverage, roughly 60 to 65 percent of code produced by AI assistants contained vulnerabilities, a rate high enough to challenge the popular idea that developers can simply "vibe code" their way to working software.

The phrase "vibe coding" has become shorthand for a fast, informal style of development where a person describes what they want and lets an AI assistant generate most of the implementation. It is attractive because it can speed up prototyping, reduce boilerplate, and help non-specialists build internal tools more quickly. But the study suggests that speed can come at the cost of basic security hygiene.

⚡ New to this?

This story is about AI-written code and why security teams are worried about it. "Vibe coding" means using an AI assistant to generate code quickly from a prompt, and an LLM, or large language model, is the type of AI that powers many of those tools.

The concern is that code can work and still be unsafe. A big issue in AI apps is prompt injection, where someone tries to trick the model by hiding malicious instructions in the text it reads.

🦞 OpenClaw angle

If you're building automations with AI-generated code — and most OpenClawsome readers are — you need to review what your AI writes. Blind trust in vibe-coded output is a security risk.

The broad finding is not that every AI-generated snippet is broken, but that insecure patterns appear often enough to be a serious default assumption. In practice, that means AI tools can produce code that functions as intended while still leaving openings for attackers, especially when the code is used in production systems rather than a throwaway prototype.

The research also points to a specific threat that has become especially important in deployed large language model systems: prompt injection. Prompt injection is a technique where an attacker manipulates an AI system by feeding it inputs that override, confuse, or redirect its instructions. In simple terms, instead of attacking the server directly, the attacker tries to trick the model into following malicious instructions hidden in the text it processes.

That matters because many AI-powered applications do not just answer questions. They also read documents, summarize messages, call tools, or make decisions based on untrusted input. If an attacker can place hostile text in a webpage, email, file, or database record, the model may treat that content as if it were part of the task itself. Security teams have been warning about this class of attack since generative AI started being deployed more widely, and the new findings reinforce why.

The study’s results also fit a broader pattern in software security. Code that looks plausible is not the same as code that resists abuse. AI assistants are good at producing syntactically valid output and can often help with routine programming work, but they do not reliably reason about threat models, access controls, input validation, or how one unsafe function can expose an entire system.

That is one reason the security impact is not limited to obvious consumer chatbots. Internal automation scripts, admin panels, data pipelines, and workflow tools can all inherit the same weaknesses if they are built quickly from AI-generated output and shipped without review. The risk grows when the code touches secrets, network access, authentication, or external APIs.

The timing of the study matters because AI-assisted development has become normal in many engineering teams. What was once treated as a coding shortcut is now embedded in daily work, from scaffolding services to writing glue code between systems. That makes the security profile of generated code a practical issue for developers, IT teams, and security reviewers, not just an abstract concern for AI researchers.

The research does not argue that AI coding tools should be abandoned. It does, however, show that the results need to be treated like any other untrusted input until a human has checked the logic, the boundaries, and the attack surface. In deployed LLM systems, prompt injection remains the most visible example of how that trust can be broken.

Source: Multiple ↗

More from Security News