Story · arXiv
Understanding the (In)Security of Vibe-Coded Applications (arXiv)
paper · Story page
The authors audited 200 publicly deployed applications built with Claude Code and Lovable, and turned up 1,186 vulnerabilities. At least one appears in 91.0% of them, which puts insecurity in the default column rather than the unlucky one.
In plain words
- Researchers checked applications made with Claude Code and Lovable and found security weaknesses.
- People build these applications by telling artificial intelligence tools what they want in everyday language.
- These tools handle much of the programming work that people would otherwise do.
- The study found weaknesses in 91.0% of the checked applications, making security a widespread concern for their users.
Appeared in
- Every audited chat tokenizer lets prompt text forge control tokens
Sep 17, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.