AI Code Is Not More Secure: 74 CVEs Tracked to AI-Generated Code, Real Number Likely 5-10x Higher

Available in: 中文
2026-03-29T19:57:13.006Z·2 min read
Georgia Tech SSLab researchers have tracked 74 CVEs definitively attributable to AI-generated code, with the actual number estimated to be 5 to 10 times higher due to detection limitations. Claude ...

Georgia Tech SSLab researchers have tracked 74 CVEs definitively attributable to AI-generated code, with the actual number estimated to be 5 to 10 times higher due to detection limitations. Claude Code leads with 49 CVEs (11 critical), followed by GitHub Copilot with 15.

The Numbers

AI ToolTotal CVEsCriticalPeriod
Claude Code4911May 2025 - Mar 2026
GitHub Copilot152Same
Aether20Same
Google Jules21Same
Devin20Same
Cursor20Same
Others21Same

The Trend

Why the Numbers Are Misleading

Researcher Hanqing Zhao: "If AI were truly responsible for only 74 out of 50,000 public vulnerabilities, that would imply AI-generated code is orders of magnitude safer than human-written code. We do not think that is credible. The low number reflects detection blind spots, not superior AI code quality."

Previous Research

Georgetown University (November 2024) tested five models and found:

The Implication

As AI coding tools explode in popularity (Claude Code alone responsible for 4%+ of GitHub commits), the security debt being accumulated is enormous — and most of it goes undetected.

Source: The Register, Georgia Tech SSLab

↗ Original source · 2026-03-29T00:00:00.000Z
← Previous: Andrew Ng's Context Hub Creates Supply Chain Attack Vector for AI Coding AgentsNext: Meta Lays Off ~700 Employees as It Redirects Billions Toward AI, Plans 20% Workforce Reduction →
Comments0