Scan of 5,600 vibe-coded apps found 2,000+ high-impact vulns, 400+ exposed secrets, PII leaks
10/10
Severity
Security Vulnerability
Failure Mode
Reproducible
No
Date
October 15, 2025
Expected Behavior
Generated apps should apply basic security fundamentals — auth, database protections, secret management, input validation.
What Actually Happened
An October 2025 scan of 5,600 publicly reachable vibe-coded apps found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of PII exposure — including medical records and bank account numbers.
Damage Assessment
AI agents produced code that worked functionally but skipped the security fundamentals experienced developers apply instinctively, at a scale spanning thousands of live applications and real corporate and personal data.
Full Report
In October 2025, API security firm Escape scanned 5,600 publicly available 'vibe-coded' applications — apps built primarily by prompting AI agents. The scan found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of PII exposure containing medical records and bank-account numbers. The systemic root cause is consistent across platforms: AI agents generate code that is functionally correct but skips the security fundamentals — authentication, database protections, secret handling, edge-case validation — that experienced engineers apply by reflex. The result is speed without safety, replicated across thousands of live applications.
Incident Metadata
- Agent
- Multiple Agents
- Failure Mode
- Security Vulnerability
- Root Cause
- Training Data Gap
- Task Type
- feature
- Domain
- backend
- Source
- benchmark