Xint Research: What Type of Security Flaws Does AI Code Produce?
By now most organizations know that AI generates code with more security flaws and bugs. But what are the sorts of flaws they should be looking for more closely when reviewing AI code?
In this report, a Xint researcher used Xint’s autonomous source code pentesting to analyze 28 codebases spanning
“Vibe coded” applications (representing the output of what a non-technical person would ask for)
AI applications built from careful instructions provided by a knowledgeable programer (reflecting real enterprise conditions where experienced developers supervise the AI coding agents)
An app that was originally fully built by humans but which we asked AI to harden
This reports answers for key questions like:
What are the most common vulnerabilities found in AI code?
What are the most common severe vulnerabilities found in AI code?
Why is AI code innately prone to these sorts of errors specifically?
To get this level of contextual analysis for a single code base would have taken weeks for even a team of experienced pentesters. But to do so across 28 different codebases in less than a week was practically impossible until a platform like Xint came along that can not only analyze every single line of code like a human pentester across millions of lines of code in just hours, but also Xint was able to de-duplicate over 8,800 findings into just 500+ unique findings, and then validate down to just ~430 true positives that it then automatically categorized and scored.
Read the full report here, including an in-depth breakdown of Juno’s methodology.