First-quarter 2026 assessment of 200 apps
183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context.
Incidents and data
The launch failure library is a sourced record of what has gone wrong in AI-built apps. Every entry maps the reported failure to what an outside check could have observed, or states plainly why it could not.
Root cause
Covered by status
183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context.
CVE entries attributed to AI-generated code rose from 6 in January 2026 to more than 35 in March 2026.
A 10 billion dollar AI startup was breached through the LiteLLM supply-chain attack, with 4 TB claimed stolen.
An allowlist bypass scored 9.9 on CVSS and was described as a full guardrail bypass.
An agent destroyed 2.5 years of production data.
More than 2,000 vulnerabilities and more than 400 exposed secrets found across vibe-coded apps.
126 malicious npm packages exploited AI-hallucinated package names.
69 vulnerabilities across 15 apps built by five AI coding tools.
An agent destroyed an entire project by looping a move command to a directory that did not exist.
An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.
An AI agent deleted and recreated an environment, causing a 13-hour outage.
An AI agent wiped production databases while explicitly instructed not to.
An unprotected storage instance exposed tens of thousands of user images, including identity documents.
Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.
Broken access control reported across 170 production applications built with Lovable.
A platform-wide authentication flaw allowed access to private enterprise data.
Run all sixteen groups on your published address and see the evidence behind every result.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026