Home / Incidents / STUPID-2026-0032
STUPID-2026-003210.0criticalMultiple AgentsVerified

Scan of 5,600 vibe-coded apps found 2,000+ high-impact vulns, 400+ exposed secrets, PII leaks

10/10
Severity
Security Vulnerability
Failure Mode
Reproducible
No
Date
October 15, 2025

Expected Behavior

Generated apps should apply basic security fundamentals — auth, database protections, secret management, input validation.

What Actually Happened

An October 2025 scan of 5,600 publicly reachable vibe-coded apps found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of PII exposure — including medical records and bank account numbers.

Damage Assessment

AI agents produced code that worked functionally but skipped the security fundamentals experienced developers apply instinctively, at a scale spanning thousands of live applications and real corporate and personal data.

Full Report

In October 2025, API security firm Escape scanned 5,600 publicly available 'vibe-coded' applications — apps built primarily by prompting AI agents. The scan found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of PII exposure containing medical records and bank-account numbers. The systemic root cause is consistent across platforms: AI agents generate code that is functionally correct but skips the security fundamentals — authentication, database protections, secret handling, edge-case validation — that experienced engineers apply by reflex. The result is speed without safety, replicated across thousands of live applications.

Incident Metadata

Agent
Multiple Agents
Failure Mode
Security Vulnerability
Root Cause
Training Data Gap
Task Type
feature
Domain
backend
Source
benchmark
View Source