Business Wire

AI-Generated Code Poses Major Security Risks in Nearly Half of All Development Tasks, Veracode Research Reveals

Share

Comprehensive Analysis of More Than 100 Large Language Models Exposes Security Gaps: Java Emerges as Highest-Risk Programming Language, While AI Misses 86% of Cross-Site Scripting Threats

Veracode, a global leader in application risk management, today unveiled its 2025 GenAI Code Security Report, revealing critical security flaws in AI-generated code. The study analyzed 80 curated coding tasks across more than 100 large language models (LLMs), revealing that while AI produces functional code, it introduces security vulnerabilities in 45 percent of cases.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250730694951/en/

Security and Syntax Pass Rates vs LLM Release from the Veracode 2025 GenAI Code Security Report

The research demonstrates a troubling pattern: when given a choice between a secure and insecure method to write code, GenAI models chose the insecure option 45 percent of the time. Perhaps more concerning, Veracode's research also uncovered a critical trend: despite advances in LLMs’ ability to generate syntactically correct code, security performance has not kept up, remaining unchanged over time.

“The rise of vibe coding, where developers rely on AI to generate code, typically without explicitly defining security requirements, represents a fundamental shift in how software is built,” said Jens Wessling, Chief Technology Officer at Veracode. “The main concern with this trend is that they do not need to specify security constraints to get the code they want, effectively leaving secure coding decisions to LLMs. Our research reveals GenAI models make the wrong choices nearly half the time, and it’s not improving.”

AI is enabling attackers to identify and exploit security vulnerabilities quicker and more effectively. Tools powered by AI can scan systems at scale, identify weaknesses, and even generate exploit code with minimal human input. This lowers the barrier to entry for less-skilled attackers and increases the speed and sophistication of attacks, posing a significant threat to traditional security defenses. Not only are vulnerabilities increasing, but the ability to exploit them is becoming easier.

LLMs Introduce Dangerous Levels of Common Security Vulnerabilities

To evaluate the security properties of LLM-generated code, Veracode designed a set of 80 code completion tasks with known potential for security vulnerabilities according to the MITRE Common Weakness Enumeration (CWE) system, a standard classification of software weaknesses that can turn into vulnerabilities. The tasks prompted more than 100 LLMs to auto-complete a block of code in a secure or insecure manner, which the research team then analyzed using Veracode Static Analysis. In 45 percent of all test cases, LLMs introduced vulnerabilities classified within the OWASP (Open Web Application Security Project) Top 10—the most critical web application security risks.

Veracode found Java to be the riskiest language for AI code generation, with a security failure rate over 70 percent. Other major languages, like Python, C#, and JavaScript, still presented significant risk, with failure rates between 38 percent and 45 percent. The research also revealed LLMs failed to secure code against cross-site scripting (CWE-80) and log injection (CWE-117) in 86 percent and 88 percent of cases, respectively.

“Despite the advances in AI-assisted development, it is clear security hasn’t kept pace,” Wessling said. “Our research shows models are getting better at coding accurately but are not improving at security. We also found larger models do not perform significantly better than smaller models, suggesting this is a systemic issue rather than an LLM scaling problem.”

Managing Application Risks in the AI Era

While GenAI development practices like vibe coding accelerate productivity, they also amplify risks. Veracode emphasizes that organizations need a comprehensive risk management program that prevents vulnerabilities before they reach production—by integrating code quality checks and automated fixes directly into the development workflow.

As organizations increasingly leverage AI-powered development, Veracode recommends taking the following proactive measures to ensure security:

  • Integrate AI-powered tools like Veracode Fix into developer workflows to remediate security risks in real time.
  • Leverage Static Analysis to detect flaws early and automatically, preventing vulnerable code from advancing through development pipelines.
  • Embed security in agentic workflows to automate policy compliance and ensure AI agents enforce secure coding standards.
  • Use Software Composition Analysis(SCA) to ensure AI-generated code does not introduce vulnerabilities from third-party dependencies and open-source components.
  • Adopt bespoke AI-driven remediation guidance to empower developers with precise fix instructions and train them to use the recommendations effectively.
  • Deploy a Package Firewall to automatically detect and block malicious packages, vulnerabilities, and policy violations.

“AI coding assistants and agentic workflows represent the future of software development, and they will continue to evolve at a rapid pace,” Wessling concluded. “The challenge facing every organization is ensuring security evolves alongside these new capabilities. Security cannot be an afterthought if we want to prevent the accumulation of massive security debt.”

The complete 2025 GenAI Code Security Report is available to download on the Veracode website.

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20250730694951/en/

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Frasca to Supply Four New Flight Training Devices to Global Medical Response15.1.2026 16:05:00 CET | Press release

New Level 7 FTDs will support pilot training for emergency medical operations Frasca International, Inc., a FlightSafety International company, today announced it has signed a contract with Global Medical Response (GMR) to supply four new Level 7 Flight Training Devices (FTDs). The new devices include an Airbus EC135, a Pilatus PC-12, a Beechcraft C90, and a Beechcraft B200. Each FTD will feature Frasca's unique motion system to provide enhanced realism in training. The devices will be installed at GMR’s new training facility currently under construction in Denton, Texas. Frasca has supported GMR’s pilot training efforts for nearly two decades, beginning with the delivery of their first device in 2005 for Air Evac Lifeteam, a GMR company. Since then, Frasca simulators have played a central role in preparing GMR’s flight crews for the complex and high-stakes environments they encounter in emergency medical operations. With the delivery of these new devices, GMR will operate a total of 1

illumynt Reports 60% Revenue Growth and Launches Global Innovation Center to Meet Rising Enterprise Security and Sustainability Demands15.1.2026 15:11:00 CET | Press release

illumynt an intelligent, security-first technology lifecycle partner, today announced significant growth and innovation milestones that position the company as a leader in the next evolution of the IT Asset Disposition (ITAD) industry—an industry increasingly shaped by artificial intelligence, accelerated hardware refresh cycles, and heightened regulatory scrutiny. Under the leadership of CEO Joerg Herbarth, illumynt continues to execute its mission to deliver intelligent, technology-driven lifecycle solutions that maximize sustainability, security, and recovery value for the world’s most compute-intensive organizations. In 2025, ITAD became a strategic imperative. AI-driven workloads have dramatically compressed infrastructure lifecycles, while updates to NIST SP 800-88 Rev. 2, adoption of R2v3, and the expansion of global privacy frameworks have raised expectations for auditability, transparency, and verified data security. As a result, ITAD has evolved from a back-end operational fu

Rimini Street Wins Multiple Industry Awards Recognizing AI Innovation, Client-First Culture, Technical Excellence and Business Impact15.1.2026 15:00:00 CET | Press release

Accolades include Tech Ascension Award for AI-Powered Agent Solution of the Year, Top Tech of the Year Award (Las Vegas), Silver Globee Award in the Customer Service Team of the Year Category and Women Leading IT Award for client, Hitachi Vantara Rimini Street, Inc., (Nasdaq: RMNI), the Software Support and Agentic AI ERP Company™, and the leading third-party support provider for Oracle, SAP and VMware software, has been recognized by top industry award programs for its innovation, technical excellence and client-first culture. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260115632021/en/ Rimini Street Wins Multiple Industry Awards Recognizing AI Innovation, Client-First Culture, Technical Excellence and Business Impact Winner of the AI-Powered Enterprise (Agent) Solution of the Year Category for Fueling Innovation and Driving Business Outcomes Rimini Street earned a 2025 Tech Ascension Award in the AI-powered Enterprise (

Lone Star Announces Sale of SENQCIA to Noritsu Koki15.1.2026 14:30:00 CET | Press release

Lone Star Funds (“Lone Star”) today announced that an affiliate of Lone Star Fund XI, L.P. has entered into a definitive agreement to sell SENQCIA Corporation (“SENQCIA”), a leading provider of mission-critical building products and solutions in Japan, to Noritsu Koki Co., Ltd., in a transaction that represents a total enterprise value of approximately $519 million. Headquartered in Tokyo, SENQCIA develops, designs and distributes essential structural solutions that enhance the resilience, integrity and long-term safety of buildings and infrastructure. The company’s diversified product portfolio serves a broad range of end-markets and property types that are used in many iconic landmark properties across Japan. SENQCIA’s solutions help address key structural challenges facing Japan, including increasing natural disaster risk and aging infrastructure and building stock. During Lone Star’s ownership, SENQCIA has enhanced its go-to-market strategy and reinforced its operational resilience

Altris and Draslovka Partner to Scale Europe’s First Sodium-Ion Battery Technology Supply Chain15.1.2026 14:00:00 CET | Press release

Altris, a Swedish sodium-ion battery developer, and Draslovka, a global leader in specialty chemicals, have entered a strategic partnership to build Europe’s first industrial-scale sodium-ion cathode value chain. Under the comprehensive agreement that includes a total 19.3 MEUR in-kind investment by Draslovka in Altris, the two companies will scale fully connected production of Altris’ patented sodium-ion cathode active material (CAM) at Draslovka’s facility in Kolín, Czech Republic, supplying up to 350 tonnes of CAM annually. Draslovka and Altris are partnering to convert an existing line at Draslovka’s Kolín facility for production of Altris’ sodium-ion CAM, enabling rapid time-to-market and capital-efficient scale-up. Once ramped, the line will support production of up to 350 tonnes annually – a European-controlled supply equivalent to around 175 MWh of sodium-ion cell capacity. As part of the agreement, Draslovka is making a new in‑kind 19.3 MEUR strategic investment in Altris to c

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye