How zero trust can help organizations contain the risks of vibe-coded applications
Key takeaways
- AI-generated code can replicate common software vulnerabilities, including exposed credentials, unsanitized inputs, missing authentication, and misconfigured security settings.
- Vibe coding can accelerate development, but pressure to ship quickly may lead teams to minimize security checks before applications reach production.
- Software buyers should assume that new applications may include AI-generated components and plan for the possibility of exploitable coding errors.
- Zero-trust security can help reduce risk by limiting each application’s access, enforcing identity at every exchange and containing the impact of a successful exploit.
AI platforms let you code fast. But is “vibe coding,” as it’s often called, unsafe at any speed? Many security professionals fear that the speed of code generation outstrips anyone’s ability to check it for errors, leading to an explosion of vulnerabilities. So, how do you keep vibe-coded applications safe to use?
Why is AI-generated code security a real business risk?
As AI has gained traction in the workplace, there have been numerous breaches related to AI-generated code vulnerabilities:
- A vibe-coded social network for AI agents, Moltbook, never enabled row-level security, exposing 1.5 million API keys.
- A pharmacy using a vibe-coded website exposed patient messages through an incorrectly configured contact form.
- A vibe-coding application known as “Orchids” contained a vulnerability that allowed security researchers remote access to user endpoints.
Survey data and real-world examples suggest that many developers now use AI tools to write code. Meanwhile, software vulnerabilities can take years to uncover. For that reason, the vulnerabilities we’ve seen so far likely represent just the tip of the iceberg.
How does AI-generated code produce vulnerabilities?
Short answer: AI-generated coding models are trained on human-generated code. Some of the training data contains vulnerabilities. Therefore, AI models can replicate these same vulnerabilities in production.
The longer answer is that AI coding tools don’t know what they don’t know. The coding model may not have been shown an example of what secure code looks like in a specific context. When a developer instructs the model to “code this module in a secure way,” the model produces code that looks plausibly secure, but which in fact contains vulnerabilities.
When we say “plausibly secure,” what we mean is that the code references libraries and uses security settings. But on closer inspection, the library is incorrect, and the security settings are misconfigured. That’s because the AI is creating output that looks like its training data instead of creating something new.
It’s important to note that the vulnerabilities produced by AI-generated code aren’t novel. Mistakes such as exposed credentials, unsanitized inputs and missing authentication are common in human-generated code, so they’re common in AI-generated code as well.
Can vibe-coded application vulnerabilities be detected?
The good news is that vibe-coded vulnerabilities are common enough that they can be spotted with the same kind of software testing and secure development practices that catch errors and insecurities in traditional code. The bad news, however, is that secure development practices might be rarer than one would hope.
A report from the Linux Foundation shows that nearly one-third of developers are unaware of secure development practices. While most developers eventually receive training in security, it can take up to five years before this occurs. In addition, research shows that most developers know that the AI-generated code they’re shipping is likely to be full of vulnerabilities. Roughly a third of developers will ship this code anyway.
The issue here is pressure. Vibe coding makes application development faster. That means that a competitive software firm can easily get its product to market first. Developers may worry that security guardrails slow development without adding clear value for buyers. So, there’s significant incentive to minimize security checks before an app goes into production.
How can software buyers safeguard vibe-coded applications?
Software buyers should assume that some components in any new applications they use in 2026 may have been vibe-coded. That doesn’t mean that they contain vulnerabilities by default. Instead, it means that purchasers should take steps to limit the fallout of any application that might contain an exploitable coding error. In other words, they should adopt zero-trust security protocols.
Zero-trust security emerged pre-AI as an assumption that every user and application was potentially compromised. In the AI era, we can now assume that every application is potentially vibe-coded, and that every vibe-coded application has exploitable vulnerabilities.
You can rigorously vet every application in your infrastructure to detect these vulnerabilities, but:
- This takes time you don’t have.
- Even the most thorough vetting can miss vulnerabilities.
- Your users are incorporating vibe-coded applications without IT approval because shadow IT never died.
By treating every application as suspect, you can design your infrastructure to limit the impact of an exploited vulnerability.
How does zero trust reduce AI-generated code security risks?
Zero-trust architecture is designed to apply enhanced authentication to every data exchange and place users and applications within narrowly defined network segments using software-defined perimeters.
Practically, this means that every application, vibe-coded or not, gets placed within its own perimeter. This perimeter defines the ways in which an application can interact with users, data and other applications. It also ensures that the application’s normal privileges only include the specific dependencies that it needs to function.
This ensures that if an application does contain an exploitable vulnerability that’s targeted by an attacker, the potential attack surface is small. What’s more, the attacker will be unable to move laterally to other applications or escalate privileges. Although the vibe-coded application may contain more vulnerabilities, the attacker remains constrained to the most basic access.
How Barracuda SecureEdge Access helps secure vibe-coded applications
Vibe coding brings with it real speed, and it may become a permanent part of the developer’s toolkit. But users will continue to bear the brunt of vulnerable applications. Companies should now assume that every new application is vibe-coded, and that every vibe-coded application is vulnerable.
Barracuda SecureEdge Access provides security leaders with the ability to place every application within a tight perimeter, while enforcing identity at every data exchange via your choice of SSO. It also gives you granular control over access, letting you determine which combination of devices, locations and users can reach a given app. Its easy deployment and stable traffic handling further distinguish Barracuda SecureEdge Access from solutions that add complexity or disrupt performance.
Although vibe-coded applications may never be truly “safe” as in free of exploitable vulnerabilities, Barracuda can help make them safe for you to use on a day-in, day-out basis. Schedule a demo and learn how Barracuda can keep your users and data safe from AI-generated exploits.
Bericht zu E-Mail-Bedrohungen 2026
Erfahren Sie, wie KI und Phishing-as-a-Service die E-Mail-Bedrohungslandschaft verändern und wie Sie sich schützen können
Abonnieren Sie den Barracuda-Blog.
Melden Sie sich an, um aktuelle Bedrohungsinformationen, Branchenkommentare und mehr zu erhalten.
Der Managed XDR Global Threat Report
Wichtige Erkenntnisse zu den Taktiken, die Angreifer verwenden, um Unternehmen anzugreifen, sowie zu den Sicherheitslücken, die sie auszunutzen versuchen