---
title: Study Finds 91 Percent of Public Vibe-Coded Web Apps Have Vulnerabilities
url: https://www.dataloco.com/en/study-finds-91-percent-of-public-vibe-coded-web-apps-have-vulnerabilities
published: 2026-10-09T16:21:15+00:00
language: en
section: Security
source: https://www.itmedia.co.jp/news/article/2610/07/2000002055/
organizations: Microsoft, National University of Singapore
publisher: Dataloco
---

# Study Finds 91 Percent of Public Vibe-Coded Web Apps Have Vulnerabilities

Researchers from Microsoft and the National University of Singapore reported that 91 percent of publicly available web applications created through automatic artificial intelligence generation contain at least one security vulnerability. The study examined 200 randomly selected applications from a pool of 984 active sites to assess the security risks associated with this rapid development method. The findings indicate that the majority of these automated systems fail to implement basic safety measures, leaving them exposed to potential threats.

The investigation focused on a specific subset of open-source projects. Out of 9041 total open-source applications, 8695 were identified as web applications. Of those, 984 were actively running in public environments. The research team selected 200 of these active sites for a detailed security audit. This sampling method allowed the researchers to evaluate the real-world security posture of applications built without traditional human coding expertise. The results showed a widespread lack of security controls across the sampled group.

Among the 1186 specific defects identified during the audit, 65.77 percent were classified as critical or high severity. These severe flaws could enable unauthorized access, system takeover, or data leakage by third parties. The high proportion of critical issues suggests that the automatic generation process often prioritizes functionality over security. This creates a significant risk for users and organizations relying on these applications for sensitive operations. The study highlights the urgent need for better security practices in automated development workflows.

The researchers categorized the causes of these vulnerabilities into three main groups. Knowledge defects accounted for 63.4 percent of the issues, occurring when the artificial intelligence ignored implicit security rules or followed dangerous user instructions. Purpose defects made up 23.1 percent, where the system prioritized quick execution over safety. Memory defects represented 13.5 percent, involving forgotten security measures or unimplemented features. These categories illustrate the specific ways in which automated systems fail to maintain consistent security standards during the development process.

Experiments to improve security outcomes showed mixed results. Without any specific instructions, 25.7 percent of vulnerabilities recurred in repeated tests. Adding a prompt requesting production-ready quality reduced this rate to 11.0 percent. Incorporating security-enhancing skills lowered the rate to 11.9 percent. However, providing detailed technical instructions worsened the situation, increasing the recurrence rate to 45.7 percent. These findings suggest that simple, high-level guidance is more effective than complex technical specifications for improving security in automated coding tasks.

The study also noted that using more advanced artificial intelligence models did not significantly improve the results. In some cases, the performance actually declined with higher-tier models. This indicates that model capability alone is not a sufficient solution to the security challenges posed by automatic application generation. The research emphasizes the need for targeted interventions and better prompting strategies to address the inherent security gaps in these systems.

## This story in other languages

- [Português (Brasil)](https://www.dataloco.com/pt-br/90-das-aplicativos-criados-com-vibe-coding-apresentam-vulnerabilidades-de-seguranca)
