Business Wire

AI-Generated Code Poses Major Security Risks in Nearly Half of All Development Tasks, Veracode Research Reveals

Share

Comprehensive Analysis of More Than 100 Large Language Models Exposes Security Gaps: Java Emerges as Highest-Risk Programming Language, While AI Misses 86% of Cross-Site Scripting Threats

Veracode, a global leader in application risk management, today unveiled its 2025 GenAI Code Security Report, revealing critical security flaws in AI-generated code. The study analyzed 80 curated coding tasks across more than 100 large language models (LLMs), revealing that while AI produces functional code, it introduces security vulnerabilities in 45 percent of cases.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250730694951/en/

Security and Syntax Pass Rates vs LLM Release from the Veracode 2025 GenAI Code Security Report

The research demonstrates a troubling pattern: when given a choice between a secure and insecure method to write code, GenAI models chose the insecure option 45 percent of the time. Perhaps more concerning, Veracode's research also uncovered a critical trend: despite advances in LLMs’ ability to generate syntactically correct code, security performance has not kept up, remaining unchanged over time.

“The rise of vibe coding, where developers rely on AI to generate code, typically without explicitly defining security requirements, represents a fundamental shift in how software is built,” said Jens Wessling, Chief Technology Officer at Veracode. “The main concern with this trend is that they do not need to specify security constraints to get the code they want, effectively leaving secure coding decisions to LLMs. Our research reveals GenAI models make the wrong choices nearly half the time, and it’s not improving.”

AI is enabling attackers to identify and exploit security vulnerabilities quicker and more effectively. Tools powered by AI can scan systems at scale, identify weaknesses, and even generate exploit code with minimal human input. This lowers the barrier to entry for less-skilled attackers and increases the speed and sophistication of attacks, posing a significant threat to traditional security defenses. Not only are vulnerabilities increasing, but the ability to exploit them is becoming easier.

LLMs Introduce Dangerous Levels of Common Security Vulnerabilities

To evaluate the security properties of LLM-generated code, Veracode designed a set of 80 code completion tasks with known potential for security vulnerabilities according to the MITRE Common Weakness Enumeration (CWE) system, a standard classification of software weaknesses that can turn into vulnerabilities. The tasks prompted more than 100 LLMs to auto-complete a block of code in a secure or insecure manner, which the research team then analyzed using Veracode Static Analysis. In 45 percent of all test cases, LLMs introduced vulnerabilities classified within the OWASP (Open Web Application Security Project) Top 10—the most critical web application security risks.

Veracode found Java to be the riskiest language for AI code generation, with a security failure rate over 70 percent. Other major languages, like Python, C#, and JavaScript, still presented significant risk, with failure rates between 38 percent and 45 percent. The research also revealed LLMs failed to secure code against cross-site scripting (CWE-80) and log injection (CWE-117) in 86 percent and 88 percent of cases, respectively.

“Despite the advances in AI-assisted development, it is clear security hasn’t kept pace,” Wessling said. “Our research shows models are getting better at coding accurately but are not improving at security. We also found larger models do not perform significantly better than smaller models, suggesting this is a systemic issue rather than an LLM scaling problem.”

Managing Application Risks in the AI Era

While GenAI development practices like vibe coding accelerate productivity, they also amplify risks. Veracode emphasizes that organizations need a comprehensive risk management program that prevents vulnerabilities before they reach production—by integrating code quality checks and automated fixes directly into the development workflow.

As organizations increasingly leverage AI-powered development, Veracode recommends taking the following proactive measures to ensure security:

  • Integrate AI-powered tools like Veracode Fix into developer workflows to remediate security risks in real time.
  • Leverage Static Analysis to detect flaws early and automatically, preventing vulnerable code from advancing through development pipelines.
  • Embed security in agentic workflows to automate policy compliance and ensure AI agents enforce secure coding standards.
  • Use Software Composition Analysis(SCA) to ensure AI-generated code does not introduce vulnerabilities from third-party dependencies and open-source components.
  • Adopt bespoke AI-driven remediation guidance to empower developers with precise fix instructions and train them to use the recommendations effectively.
  • Deploy a Package Firewall to automatically detect and block malicious packages, vulnerabilities, and policy violations.

“AI coding assistants and agentic workflows represent the future of software development, and they will continue to evolve at a rapid pace,” Wessling concluded. “The challenge facing every organization is ensuring security evolves alongside these new capabilities. Security cannot be an afterthought if we want to prevent the accumulation of massive security debt.”

The complete 2025 GenAI Code Security Report is available to download on the Veracode website.

About Veracode

Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.

Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.

Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.

View source version on businesswire.com: https://www.businesswire.com/news/home/20250730694951/en/

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Rimini Street Announces Fiscal Second Quarter 2025 Financial and Operating Results31.7.2025 22:01:00 CEST | Press release

Second Quarter Financial Highlights Include: Gross margin of 60.4% compared to 59.1% in the prior year Adjusted Calculated Billings of $107.9 million compared to $103.8 million in the prior year Adjusted EBITDA of $13.0 million compared to $8.8 million in the prior year Revenue Retention Rate of 90% compared to 88% in the prior year Rimini Street, Inc., (the “Company”) (Nasdaq: RMNI), a global provider of end-to-end enterprise software support and innovation solutions, and the leading third-party support provider for Oracle, SAP and VMware software, today announced results for the fiscal second quarter ended June 30, 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250731791846/en/ Rimini Street Announces Fiscal Second Quarter 2025 Financial and Operating Results Select Second Quarter 2025 Financial Results Revenue was $104.1 million for the 2025 second quarter, an increase of 1.0% compared to $103.1 million for the same

Altasciences and VoxCell BioInnovation Announce Strategic Collaboration to Advance Preclinical Drug Development31.7.2025 20:56:00 CEST | Press release

Altasciences, a fully integrated drug development solution company, and VoxCell BioInnovation (“VoxCell”), a leader in 3D bioprinting and human-like tissue modeling, are pleased to announce a strategic collaboration aimed at enhancing preclinical research and accelerating the path from discovery to clinical trials. This partnership combines Altasciences’ comprehensive early-phase drug development capabilities with VoxCell’s cutting-edge 3D tissue technology to offer a more predictive and human-relevant preclinical testing environment. By integrating VoxCell’s high-resolution 3D bioprinted tissue platforms into Altasciences’ discovery and preclinical services, both companies aim to reduce R&D timelines and increase the success rate of investigational therapies. “We’re proud to partner with VoxCell BioInnovation to bring next-generation tissue modeling into the early stages of drug development,” said Steve Mason, Co-Chief Operating Officer at Altasciences. “This collaboration aligns with

GEA Raises Forecast for Fiscal Year 2025 and Provides Positive Outlook31.7.2025 19:40:00 CEST | Press release

Due to a very positive operating performance in the first 6 months and expectations for the remainder of the financial year 2025, GEA Group Aktiengesellschaft is raising all guidance parameters based on preliminary figures as follows: Organic sales growth 2 to 4 percent (previously 1 to 4 percent), EBITDA-margin before restructuring expenses 16.2 to 16.4 percent (previously 15.6 to 16.0 percent) and ROCE 34 to 38 percent (previously 30 to 35 percent). The company will publish its complete statement for the 2nd quarter (half-year financial report) on August 7, 2025. “Our positive development continues. The additional improvements are broad-based, supported by a favorable order situation as well as margin improvements and efficiency gains across the Group. Once again, we are thus demonstrating our strength in executing on our plans,” said GEA CEO Stefan Klebert. Alongside improving the profitability indicators EBITDA margin before restructuring expenses and ROCE, GEA also increased order

Global Technology Leaders Adopt Access Advance's Video Distribution Patent Pool31.7.2025 18:58:00 CEST | Press release

A diverse group of global companies across the video ecosystem has joined Access Advance's Video Distribution Patent ("VDP") Pool and is now sharing why they selected this pool. Positioned as a balanced, transparent, and comprehensive video codec licensing solution for the video streaming industry, the pool brings together major patent holders, video platform operators, and stakeholders in the consumer device market in an effort to help the industry navigate the complex licensing challenges in the rapidly evolving video distribution markets. The VDP Pool has attracted an unprecedented list of industry leaders as both licensors and licensees, including ByteDance, Dolby, JVC Kenwood, Kuaishou, HFI (an affiliate of MediaTek), Mitsubishi, OPPO, Philips, Tencent, and other major technology companies. This broad participation spans the entire video ecosystem, from content platforms serving billions of users to semiconductor companies powering video devices worldwide. Collaborative Framework

Interactive Brokers Launches Version 1.0 of IBKR Desktop, Delivering a Comprehensive Trading Experience in One Platform31.7.2025 16:00:00 CEST | Press release

New platform combines market intelligence, product discovery, and execution tools in a modern, scalable interface Interactive Brokers (Nasdaq: IBKR), an automated global electronic broker, today announced the official launch of Version 1.0 of IBKR Desktop, a next-generation trading platform that balances simplicity with advanced functionality. This release follows two years of iterative beta development and introduces a fully featured desktop trading experience for investors worldwide. IBKR Desktop is designed to serve as a primary trading platform for both retail and professional clients. It combines all key trading workflow components, including discovery, analysis, execution, and portfolio management, in a powerful and intuitive interface. “We built IBKR Desktop to meet the needs of all investors, from experienced traders to those just getting started,” said Milan Galik, Chief Executive Officer of Interactive Brokers. “With this release, we are delivering a platform that is easy to

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye