STUPID-2026-0032

Scan of 5,600 vibe-coded apps found 2,000+ high-impact vulns, 400+ exposed secrets, PII leaks

10.0critical
October 15, 2025Verified
  1. Instruction given

    Build production web applications by prompting AI agents ('vibe coding').

  2. Expected behavior

    Generated apps should apply basic security fundamentals — auth, database protections, secret management, input validation.

  3. Actual behavior

    An October 2025 scan of 5,600 publicly reachable vibe-coded apps found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of PII exposure — including medical records and bank account numbers.

  4. Damage

    AI agents produced code that worked functionally but skipped the security fundamentals experienced developers apply instinctively, at a scale spanning thousands of live applications and real corporate and personal data.

In October 2025, API security firm Escape scanned 5,600 publicly available 'vibe-coded' applications — apps built primarily by prompting AI agents. The scan found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of PII exposure containing medical records and bank-account numbers. The systemic root cause is consistent across platforms: AI agents generate code that is functionally correct but skips the security fundamentals — authentication, database protections, secret handling, edge-case validation — that experienced engineers apply by reflex. The result is speed without safety, replicated across thousands of live applications.

Classification

Domain
Backend
Source
Benchmark

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.