medium80% confidenceseed
Georgia Tech tracking confirms AI coding tools in the provenance of public CVEs.
CapabilityDomain knowledgeImpact domainCap-adjacent
Quoted text
We've been tracking public CVEs where AI-generated code introduced the vulnerability. 50k+ advisories scanned. Dozens of confirmed cases so far. Claude Code, Copilot, Cursor, and others all show up. Common bug classes include XSS, command injection, SSRF, and path traversal.
Read and engage with the original on X. This desk is not a republication feed.
Analyst rationale
Measured, not anecdotal: AI-authored code is already landing classic injection classes in shipped software. The vulnerability is in the codegen system and the review process that trusts it.
Related signals
CapabilityDomain knowledgeAffordanceImpact domainCap-adjacent
CapabilityDomain knowledgeAffordanceImpact domainCap-adjacent
CapabilityDomain knowledgeAffordanceImpact domainCap-adjacent
CapabilityAffordanceImpact domainBoth