Vibe coding’s security blind spots raise concerns as developers report hidden vulnerabilities
Developers using AI to build apps report SQL injection flaws, exposed databases, and accidental production deletions, highlighting the gap between speed and security in ‘vibe coding’ workflows.
1 source · cross-referenced
- A project manager’s AI-built website contained a hidden SQL injection risk that went unnoticed for months after launch.
- Security researchers found thousands of AI-generated apps publicly exposing sensitive data, including medical and financial records.
- Experts warn that AI-assisted coding tools lack built-in security reviews, leaving casual developers vulnerable to breaches.
Bob Starr, a project manager, built a website called “Boomberg” using an AI coding tool and launched it immediately after creation. Months later, he discovered a hidden SQL injection vulnerability that could have allowed attackers to access or alter data. Starr described the oversight as a “glaring blind spot” in his understanding of the new technology, emphasizing that others may be making similar mistakes as they adopt AI-assisted coding. He later fixed the issue.
Across social media, developers have shared similar experiences. Jer Crane, founder of PocketOS, reported that an AI coding agent accidentally wiped out his company’s production database. Joe Procopio, a serial entrepreneur, vibe-coded a web app to privately demo other projects but took it offline after hackers breached it, later reverting to traditional methods for demos.
Security experts highlight a broader pattern of vulnerabilities in AI-generated apps. Gabriel Bernadett-Shapiro, a distinguished AI research scientist at SentinelOne, noted that the risk escalates when personal apps transition into business use, particularly those handling customer logs, medical data, financial records, or internal documents. He stressed that such apps require stricter security standards, regardless of how quickly they were built.
Jack Cable, CEO and cofounder of Corridor, echoed this concern, stating that vibe coding is suitable for low-risk prototypes but inadequate for handling sensitive or publicly exposed data. He advised developers to consider threat models and err on the side of caution when security is uncertain.
Max Segall, COO of crypto wallet firm Privy, shared a near-miss where a colleague identified a critical flaw in EzRun, an AI-built app designed to reward his child with Ethereum for running. The flaw could have allowed attackers to modify user accounts. Segall emphasized the importance of proactive security reviews in AI-assisted development.
High-profile cases further illustrate the risks. In January, Matt Schlicht launched Moltbook, a social network built entirely for AI agents without any manually written code. Within days, security firm Wiz discovered the app’s production database was entirely exposed, leaking tens of thousands of email addresses and private messages. Moltbook patched the vulnerability after being notified.
Researchers at cybersecurity firm Red Access reported finding roughly 5,000 publicly accessible apps built with popular vibe-coding tools that lacked authentication, with nearly 2,000 leaking sensitive data such as medical and financial information, strategy documents, and chatbot conversation logs.
Experts note that while professionally developed software often has security flaws, the proliferation of AI-assisted coding exponentially increases the volume of apps—and thus the potential attack surface. They warn that AI tools may provide a false sense of security, as developers might assume the AI-generated code is safe without additional scrutiny. Security tools like Claude Code’s /security-review command or OpenAI’s Codex Security agent require manual setup and are often not used by casual developers.
- Jun 22, 2026 · The Verge — AI
AI-enhanced real estate listings raise renter concerns over misleading visuals
Trust72 - Jun 22, 2026 · Wired
Meta investigates internal exposure of employee keystroke data collected for AI training
Trust79 - Jun 20, 2026 · The Verge — AI
The Atlantic publishes searchable database of music used to train AI models
Trust79