AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to signals
medium80% confidenceseed

Georgia Tech tracking confirms AI coding tools in the provenance of public CVEs.

CapabilityDomain knowledgeImpact domainCap-adjacent
Quoted from XHanqing Zhao@hanqing25 Mar 2026, 20:09

Quoted text

We've been tracking public CVEs where AI-generated code introduced the vulnerability. 50k+ advisories scanned. Dozens of confirmed cases so far. Claude Code, Copilot, Cursor, and others all show up. Common bug classes include XSS, command injection, SSRF, and path traversal.

Read and engage with the original on X. This desk is not a republication feed.

Analyst rationale

Measured, not anecdotal: AI-authored code is already landing classic injection classes in shipped software. The vulnerability is in the codegen system and the review process that trusts it.

Related signals

Contributes to