The AI code vulnerabilities that grow with your app Theori built 28 apps using AI coding agents from Anthropic and OpenAI and found that while the models avoided common injection flaws like SQL injection and cross-site scripting, they introduced other vulnerabilities that grow with the application. The security firm tested apps built from a spec, a casual prompt, and a rewritten PHP codebase, scanning each through its pentesting platform. Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The team went in expecting injection everywhere. SQL injection, cross-site scripting, the bugs that fill security tutorials. Those barely showed up. The models reached for prepared statements and ORMs on … More https://www.helpnetsecurity.com/2026/07/23/report-ai-code-vulnerabilities/ The post The AI code vulnerabilities that grow with your app https://www.helpnetsecurity.com/2026/07/23/report-ai-code-vulnerabilities/ appeared first on Help Net Security https://www.helpnetsecurity.com .