security
Apr 6, 2026
By Teun
Research Finds 60–65% of AI-Generated "Vibe Code" Is Vulnerable
A study found the majority of code written by AI assistants contains security vulnerabilities, with prompt injection being the top threat in deployed LLM systems. The findings challenge the growing "just vibe code it" trend.
A new security study is putting hard numbers on a problem many engineers have seen firsthand: AI-generated code often looks finished before it is actually safe. According to the research highlighted in recent AI news coverage, roughly 60 to 65 percent of code produced by AI assistants contained vulnerabilities, a rate high enough to challenge the popular idea that developers can simply "vibe code" their way to working software.
The phrase "vibe coding" has become shorthand for a fast, informal style of development where a person describes what they want and lets an AI assistant generate most of the implementation. It is attractive because it can speed up prototyping, reduce boilerplate, and help non-specialists build internal tools more quickly. But the study suggests that speed can come at the cost of basic security hygiene.
The broad finding is not that every AI-generated snippet is broken, but that insecure patterns appear often enough to be a serious default assumption. In practice, that means AI tools can produce code that functions as intended while still leaving openings for attackers, especially when the code is used in production systems rather than a throwaway prototype.
The research also points to a specific threat that has become especially important in deployed large language model systems: prompt injection. Prompt injection is a technique where an attacker manipulates an AI system by feeding it inputs that override, confuse, or redirect its instructions. In simple terms, instead of attacking the server directly, the attacker tries to trick the model into following malicious instructions hidden in the text it processes.
That matters because many AI-powered applications do not just answer questions. They also read documents, summarize messages, call tools, or make decisions based on untrusted input. If an attacker can place hostile text in a webpage, email, file, or database record, the model may treat that content as if it were part of the task itself. Security teams have been warning about this class of attack since generative AI started being deployed more widely, and the new findings reinforce why.
The study’s results also fit a broader pattern in software security. Code that looks plausible is not the same as code that resists abuse. AI assistants are good at producing syntactically valid output and can often help with routine programming work, but they do not reliably reason about threat models, access controls, input validation, or how one unsafe function can expose an entire system.
That is one reason the security impact is not limited to obvious consumer chatbots. Internal automation scripts, admin panels, data pipelines, and workflow tools can all inherit the same weaknesses if they are built quickly from AI-generated output and shipped without review. The risk grows when the code touches secrets, network access, authentication, or external APIs.
The timing of the study matters because AI-assisted development has become normal in many engineering teams. What was once treated as a coding shortcut is now embedded in daily work, from scaffolding services to writing glue code between systems. That makes the security profile of generated code a practical issue for developers, IT teams, and security reviewers, not just an abstract concern for AI researchers.
The research does not argue that AI coding tools should be abandoned. It does, however, show that the results need to be treated like any other untrusted input until a human has checked the logic, the boundaries, and the attack surface. In deployed LLM systems, prompt injection remains the most visible example of how that trust can be broken.