Media & Culture

Vibe-coded apps expose SQL injection, database wipes, and 5,000+ leaks

AI-built apps are flooding the web—and hackers are loving it.

Deep Dive

A wave of 'vibe-coded' AI apps is introducing serious security flaws. Bob Starr's site had a hidden SQL injection risk; Jer Crane's PocketOS production DB was wiped; Joe Procopio's demo app was hacked. SentinelOne's Gabriel Bernadett-Shapiro warns that personal apps can drift into business software without security. Jack Cable of Corridor says public internet apps need threat modeling. Wiz found Moltbook's entire production database wide open, exposing tens of thousands of email addresses and private messages. The lesson: vibe coding massively boosts app creation, but also the number of security risks.

Key Points
  • Bob Starr's vibe-coded 'Boomberg' site had a hidden SQL injection vulnerability, risking data alteration.
  • Jer Crane's PocketOS production database was wiped by an AI coding agent; Joe Procopio's demo app was hacked, forcing a return to local demos.
  • Wiz found Moltbook's production database fully open, exposing tens of thousands of emails and private messages.

Why It Matters

AI makes app creation effortless, but security is still manual—one flaw can leak thousands of users' data.

📬 Get the top 10 AI stories daily