STUPID-2026-0032
Scan of 5,600 vibe-coded apps found 2,000+ high-impact vulns, 400+ exposed secrets, PII leaks
Instruction given
Build production web applications by prompting AI agents ('vibe coding').
Expected behavior
Generated apps should apply basic security fundamentals — auth, database protections, secret management, input validation.
Actual behavior
An October 2025 scan of 5,600 publicly reachable vibe-coded apps found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets including API keys and access tokens, and 175 instances of PII exposure — including medical records and bank account numbers.
Damage
AI agents produced code that worked functionally but skipped the security fundamentals experienced developers apply instinctively, at a scale spanning thousands of live applications and real corporate and personal data.
Classification
- Agent
- Multiple Agents
- Failure mode
- Security Vulnerability
- Root cause
- Training Data Gap
- Domain
- Backend
- Source
- Benchmark
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.