cd /news/ai-safety/xint-research-what-type-of-security-… · home topics ai-safety article
[ARTICLE · art-68733] src=xint.io ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Xint Research: What Type of Security Flaws Does AI Code Produce?

Xint Research analyzed 28 AI-generated codebases and found that the most common vulnerabilities include injection flaws, broken access control, and cryptographic issues, with AI code being inherently prone to these errors due to lack of context and security awareness. The study, which used Xint's autonomous source code pentesting platform, de-duplicated over 8,800 findings into 500+ unique findings and validated 430 true positives across vibe-coded apps, enterprise AI applications, and human-built apps hardened by AI.

read1 min views1 publishedJul 22, 2026
Xint Research: What Type of Security Flaws Does AI Code Produce?
Image: Xint (auto-discovered)

By now most organizations know that AI generates code with more security flaws and bugs. But what are the sorts of flaws they should be looking for more closely when reviewing AI code?

In this report, a Xint researcher used Xint’s autonomous source code pentesting to analyze 28 codebases spanning

“Vibe coded” applications (representing the output of what a non-technical person would ask for)

AI applications built from careful instructions provided by a knowledgeable programer (reflecting real enterprise conditions where experienced developers supervise the AI coding agents)

An app that was originally fully built by humans but which we asked AI to harden

This reports answers for key questions like:

What are the most common vulnerabilities found in AI code?

What are the most common

vulnerabilities found in AI code?severeWhy is AI code innately prone to these sorts of errors specifically?

To get this level of contextual analysis for a single code base would have taken weeks for even a team of experienced pentesters. But to do so across 28 different codebases in less than a week was practically impossible until a platform like Xint came along that can not only analyze every single line of code like a human pentester across millions of lines of code in just hours, but also Xint was able to de-duplicate over 8,800 findings into just 500+ unique findings, and then validate down to just ~430 true positives that it then automatically categorized and scored.

Read the full report here, including an in-depth breakdown of Juno’s methodology.

── more in #ai-safety 4 stories · sorted by recency
── more on @xint research 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/xint-research-what-t…] indexed:0 read:1min 2026-07-22 ·