Vibe-coded apps expose SQL injection, database wipes, and 5,000+ leaks
AI-built apps are flooding the web—and hackers are loving it.
A wave of 'vibe-coded' AI apps is introducing serious security flaws. Bob Starr's site had a hidden SQL injection risk; Jer Crane's PocketOS production DB was wiped; Joe Procopio's demo app was hacked. SentinelOne's Gabriel Bernadett-Shapiro warns that personal apps can drift into business software without security. Jack Cable of Corridor says public internet apps need threat modeling. Wiz found Moltbook's entire production database wide open, exposing tens of thousands of email addresses and private messages. The lesson: vibe coding massively boosts app creation, but also the number of security risks.
- Bob Starr's vibe-coded 'Boomberg' site had a hidden SQL injection vulnerability, risking data alteration.
- Jer Crane's PocketOS production database was wiped by an AI coding agent; Joe Procopio's demo app was hacked, forcing a return to local demos.
- Wiz found Moltbook's production database fully open, exposing tens of thousands of emails and private messages.
Why It Matters
AI makes app creation effortless, but security is still manual—one flaw can leak thousands of users' data.