VibeCoded

What security holes do AI-built apps have?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

The most common are missing authorization (one user reaching another's data), open database rules, secret keys in front-end code, checks done only in the browser, no rate limits, unsafe handling of user input and model output, and logic errors in payments. They share a cause: the tool writes code that satisfies the prompt and the demo, and nobody asked it what an attacker would try.

The holes, in order of how often they matter

Common vulnerabilities in AI-built apps
HoleWhat an attacker doesDetail
Missing authorization (IDOR)Changes an ID to read or edit someone else's recordIDOR
Open database rulesQueries tables directly with the public keyRLS mistakes
Secrets in the browserCopies a payment, AI or admin key from the JavaScriptExposed keys
Front-end-only checksCalls the API the hidden button would have calledClient-side authorization
No rate limitsGuesses passwords, floods sign-ups, runs up your AI billRate limiting
InjectionPuts code or query fragments into inputsSQL injection, XSS
Payment logicChanges the price or skips paymentStripe
Unsafe uploadsUploads a file that runs or overwrites othersUploads
Prompt injectionInstructs your AI feature to leak data or misuse toolsPrompt injection
Made-up dependenciesRegisters a package name the AI inventedAI-suggested packages

Why AI tools produce these

They are optimised to make code that runs and matches the request. Authorization, limits and validation are constraints nobody states in a prompt, so they are left out or half-done. The tools also borrow patterns from public code, including insecure defaults. Broken access control is first on the OWASP Top 10 for web applications for all software, not only AI-written code; AI simply produces more code with less review.

How they are found

Most need a person with two accounts and an idea of what the app should allow. Scanners find the configuration items and miss the logic. See whether a scanner is enough.

Fix them in this order

  1. Close anything that exposes data without login: open database rules, public buckets, leaked service keys.
  2. Close cross-user and cross-customer access.
  3. Move every secret server-side and rotate any that leaked.
  4. Fix payment trust: server-side prices and verified webhooks.
  5. Add rate limits and AI usage caps.
  6. Treat AI input and output as untrusted.
  7. Clean up error messages, headers and dependencies.

The first three account for most of the serious incidents involving AI-built apps that have been made public. They are also the quickest to check with the pre-launch security checklist.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

Are AI-built apps less secure than hand-written ones?

Not inherently. The same holes appear in hand-written code. The difference is that nobody reviewed the AI's code as it was written, so they reach production more often.

Which one should I check first?

Authorization between users. It is the most common and the most damaging.