Understanding the (In)Security of Vibe-Coded Applications
cs.CR, cs.SE
Submitted: 2026-06-22
Updated: 2026-09-14
Code: https://github.com/openai/codex
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering
- Building Software by Rolling the Dice: A Qualitative Study of Vibe Coding
- Is Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World Tasks
- SeCodePLT: A Unified Platform for Evaluating the Security of Code GenAI
- How Secure is Code Generated by ChatGPT?
- LLM-CSEC: Empirical Evaluation of Security in C/C++ Code Generated by Large Language Models
- The Hidden Risks of LLM-Generated Web Application Code: A Security-Centric Evaluation of Code Generation Capabilities in Large Language Models
- A.S.E: A Repository-Level Benchmark for Evaluating Security in AI-Generated Code
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs