STUPID-2026-0022

AI vibe-coded Next.js app pinned vulnerable dependency — cryptominer compromised production server

10.0critical
March 22, 2026Verified
  1. Instruction given

    Build a Next.js web service from functional descriptions

  2. Expected behavior

    A secure, deployable web service using appropriate dependency versions

  3. Actual behavior

    AI pinned next@14.1.0 (or equivalent vulnerable version) with CVE-2025-29927, which was deployed and exploited to run a cryptominer in production

  4. Damage

    Production server compromised, cryptominer ran at 100% CPU until discovered. Remediated after incident.

A developer used an AI coding agent to build a Next.js web service via 'vibe coding' (building from functional descriptions). The agent pinned a dependency version that contained CVE-2025-29927, a Next.js middleware bypass vulnerability. The code passed all functional tests. The vulnerable version was deployed to production and subsequently exploited: an attacker used the CVE to deploy a cryptominer that ran the server at ~100% CPU continuously. The author notes the AI had no cost model for what dependency version selection means at runtime.

Classification

Domain
Frontend
Language
Javascript

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.