91% of Vibe-Coded Web Apps Had Vulnerabilities
- •Researchers randomly tested 200 publicly running web apps built through vibe coding.
- •They found vulnerabilities in 91% of apps; 65.77% of 1,186 flaws were critical or high severity.
- •Repeated vulnerabilities fell to 11.0% with a production-ready prompt, but rose to 45.7% with detailed technical instructions.
Researchers from Microsoft, the National University of Singapore and other institutions published a study on October 7, 2026, examining vulnerabilities in AI-generated web apps built through “vibe coding.” The approach generates an entire app from natural-language instructions, allowing people without programming expertise to publish apps while raising security concerns.
The team identified 8,695 web apps among 9,041 open-source apps. From 984 publicly running web apps, researchers randomly selected 200 for testing. They found at least one vulnerability in 91% of them. The 1,186 flaws identified included 65.77% classified as “critical” or “high.” The report said these flaws could enable unauthorized access, system takeovers or data leaks.
Researchers grouped the causes into three types. Memory failures accounted for 13.5% and involved security measures decided during development being forgotten or left unimplemented before release. Goal failures accounted for 23.1% and involved choosing improper handling to make an app work quickly rather than prioritizing security. Knowledge failures were the most common, at 63.4%; they included overlooking unstated security rules or following dangerous instructions.
In tests where AI repeated the same task, the chance that the same vulnerability reappeared was 25.7% without special measures. Adding “make it production-ready” to the prompt reduced the rate to 11.0%, while adding a security-enhancement skill lowered it to 11.9%. By contrast, writing more detailed technical instructions raised the recurrence rate to 45.7%. Switching to a higher-level AI model brought little improvement, and researchers also observed cases that worsened. The paper is titled “Understanding the (In)Security of Vibe-Coded Applications” and was published on arXiv in 2026. Cybersecurity means protecting computers, networks and data from attacks or misuse. A prompt is text that instructs an AI system. An AI agent is a system that carries out multiple steps toward a task on its own.
The report gives the number of publicly running apps tested, the count and severity of vulnerabilities, the shares by cause, and the recurrence rates from the experiments. Researchers reported lower recurrence after adding a brief production-readiness requirement or a security-enhancement skill to prompts, and higher recurrence after adding detailed technical instructions.