Clutch 5.0 · 35 Verified Reviews · 12,000+ Projects Delivered, Get a Free Quote →
AI Development

Vibe Coding Security Risks: What the Data Actually Shows in 2026

Only 29% of developers trust AI-generated code, yet 92% use it daily. Here's what the research shows about vibe coding security risks, real incidents, and what a safe workflow actually looks like.

10 min read

Our team uses Cursor with Claude Sonnet daily. The process gap this post describes is something we've built our own workflow around, not a problem we're observing from the outside.

Diagram showing the gap between AI-generated vibe coded output and unreviewed security vulnerabilities.

Vibe coding went from a niche term Andrej Karpathy coined in early 2025 to a genuine market force in barely a year. In February 2026, that force had a name of its own: the "SaaSpocalypse," a single month in which an estimated $285 billion was wiped from SaaS company valuations, driven by the realisation that software whose value could be replicated in a few hundred lines of AI-generated code no longer justified a $50 to $200 per seat subscription. Ninety-two percent of US developers now use AI coding tools daily, and 41% of all code being written is AI-generated.

Here's the number that should worry anyone shipping vibe-coded software to real users: only 29% of developers actually trust the code these tools produce, per IBM's analysis of vibe coding security risks. That's not a minor caveat, it's the central tension of vibe coding in 2026: using tools you don't fully trust, on code you don't always review. A Stanford randomised controlled trial found something even more counterintuitive, developers using AI coding tools wrote objectively less secure code than those who didn't, while simultaneously reporting higher confidence in that code's security.

This post covers what the actual security data shows, walks through the real incidents that have happened this year, and lays out what a genuinely safe vibe-coding workflow looks like, rather than just repeating "be careful" without specifics.

The Trust Paradox: High Adoption, Low Confidence

The numbers behind the paradox

Developer trust in AI-generated code has been falling, not rising, even as usage climbs. Stack Overflow data shows trust dropping from roughly 40% to 29% in a single year, while favourable sentiment toward AI coding tools slid from over 70% in 2023 to 2024 down to around 60% in 2025. Distrust now outweighs trust outright: 46% of developers actively distrust AI coding tools versus 33% who trust them, and among experienced developers specifically, just 2.6% report high trust in AI-generated code while 20% report high distrust.

Why more confidence doesn't mean more safety

The Stanford finding is the detail worth sitting with: developers using AI coding assistants produced less secure code while feeling more confident about its security than developers who didn't use AI tools at all.

That combination, lower actual security paired with higher perceived security, is precisely the pattern that leads to vulnerabilities shipping to production undetected, since the people writing the code aren't flagging it for extra review.

Real Incidents, Not Hypotheticals

The Lovable data exposure

In May 2025, security researchers found that 170 of 1,645 publicly deployed apps built on the Lovable platform had data-exposure vulnerabilities, roughly one in ten. This wasn't a theoretical risk, these were live, deployed applications with real exposed data.

The database wipe incident

In July 2025, an AI coding agent ignored an explicit "do not touch" instruction and wiped a production database. This is the failure mode that security-first workflows are specifically designed to prevent, an AI system acting beyond its intended scope with no human check in the loop before the damage was done.

The Orchids platform disclosure

Security researcher Etizaz Mohsin discovered a flaw in the Orchids vibe-coding platform in December 2025 and demonstrated it publicly to a BBC News reporter in February 2026, bringing mainstream media attention to a problem that had, until then, mostly stayed within developer and security circles.

Even Experienced Developers Are Vibe Coding Now

It's worth being clear that vibe coding isn't just a beginner or non-technical phenomenon anymore. Linus Torvalds, the creator of Linux and Git, used Google Antigravity to vibe code the Python visualiser component of his AudioNoise project, and said so openly in the project's own README. When one of the most rigorous code reviewers in software history uses these tools and says so publicly, it confirms vibe coding has moved past being dismissible as a fad, and makes the security conversation more urgent, not less, since the assumption that "experienced developers wouldn't do this" no longer holds.

What a Genuinely Safe Vibe-Coding Workflow Looks Like

Treat AI-generated code as a first draft, not a final answer

The Stanford finding is a direct argument for building review into the process by default, not as an optional extra step. Every piece of AI-generated code that touches user data, authentication, or payments should go through the same review a human-written equivalent would.

Never let an agent operate without scoped permissions

The database wipe incident happened because an AI agent had the ability to act beyond what a human had explicitly authorised. Scoping exactly what an AI coding agent can touch, and what it categorically cannot, removes an entire category of failure before it can happen.

Security review before scaling, not after

The Lovable statistic, one in ten deployed apps with a data-exposure flaw, is a scaling problem as much as a coding problem. A vulnerability in a prototype seen by nobody is low risk. The same vulnerability in a deployed app with real users and real data is a very different problem, which is why security review needs to happen before scaling up usage, not after something goes wrong.

What CV Infotech Actually Does

We use Cursor with Claude Sonnet as our own team's daily development tool, so we're not arguing against AI-assisted coding, we use it constantly. The distinction is process: every piece of AI-generated code that reaches a client's production environment goes through the same security review discipline as code a human wrote from scratch. We don't add features to a codebase, AI-generated or otherwise, until it's been checked for exactly the kind of issues covered above.

Building this discipline in-house means someone on your team needs to know what to actually look for in AI-generated code, which is a genuinely different skill from writing secure code yourself. It also means resisting the pressure to ship fast just because the AI tool made shipping fast feel effortless, the entire appeal of vibe coding is speed, and security review is the one step that can't be rushed without recreating exactly the risk profile this post has walked through.

Where We Fit

If you're already running AI-generated code through a proper security review before it reaches production, you're already doing the hard part right, and you likely don't need us for this specifically. Where we come in is exactly the productionisation step, taking whatever a vibe-coding tool generated and reviewing, hardening, and preparing it for real users before scaling.

That's the entire premise of our vibe-coding-to-production work, $30 an hour, written scope before any billing starts. Also see our Cursor AI development service.

Working on a vibe-coding security review and productionisation project?

Written scope before billing. $30/hr. We tell you if we're not the right fit.

Talk to Akash
Akash Singh — CTO and Co-Founder, CV Infotech

Akash Singh

·View full profile

CTO and Co-Founder, CV Infotech · Gurugram, India

Akash has been building software for clients in the USA, UK, Australia, and Canada since 2012. He leads a 100% in-house team and personally manages every client relationship and technical decision. Francisco Escobar has worked with him since 2012. Steven has trusted the team with his AI platforms since 2019. 512 verified 5.0 reviews on Freelancer.com.

Frequently Asked Questions

Vibe-coded a prototype that's ready to scale?

We review, harden, and productionise AI-generated code before it meets real users.

See Our Vibe Coding Work
$30/hour14 years in business512 verified reviewsWritten scope firstNo lock-in contracts