cd /news/ai-safety/the-ai-code-vulnerabilities-that-gro… · home topics ai-safety article
[ARTICLE · art-69651] src=helpnetsecurity.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

The AI code vulnerabilities that grow with your app

Theori built 28 apps using AI coding agents from Anthropic and OpenAI and found that while the models avoided common injection flaws like SQL injection and cross-site scripting, they introduced other vulnerabilities that grow with the application. The security firm tested apps built from a spec, a casual prompt, and a rewritten PHP codebase, scanning each through its pentesting platform.

read1 min views1 publishedJul 23, 2026

Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The team went in expecting injection everywhere. SQL injection, cross-site scripting, the bugs that fill security tutorials. Those barely showed up. The models reached for prepared statements and ORMs on … More

The post The AI code vulnerabilities that grow with your app appeared first on Help Net Security.

── more in #ai-safety 4 stories · sorted by recency
── more on @theori 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/the-ai-code-vulnerab…] indexed:0 read:1min 2026-07-23 ·