AI-Generated Code Poses Major Security Risks in Nearly Half of All Development Tasks, Veracode Research Reveals
30.7.2025 14:50:00 EEST | Business Wire | Press release
Veracode, a global leader in application risk management, today unveiled its 2025 GenAI Code Security Report, revealing critical security flaws in AI-generated code. The study analyzed 80 curated coding tasks across more than 100 large language models (LLMs), revealing that while AI produces functional code, it introduces security vulnerabilities in 45 percent of cases.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250730694951/en/
Security and Syntax Pass Rates vs LLM Release from the Veracode 2025 GenAI Code Security Report
The research demonstrates a troubling pattern: when given a choice between a secure and insecure method to write code, GenAI models chose the insecure option 45 percent of the time. Perhaps more concerning, Veracode's research also uncovered a critical trend: despite advances in LLMs’ ability to generate syntactically correct code, security performance has not kept up, remaining unchanged over time.
“The rise of vibe coding, where developers rely on AI to generate code, typically without explicitly defining security requirements, represents a fundamental shift in how software is built,” said Jens Wessling, Chief Technology Officer at Veracode. “The main concern with this trend is that they do not need to specify security constraints to get the code they want, effectively leaving secure coding decisions to LLMs. Our research reveals GenAI models make the wrong choices nearly half the time, and it’s not improving.”
AI is enabling attackers to identify and exploit security vulnerabilities quicker and more effectively. Tools powered by AI can scan systems at scale, identify weaknesses, and even generate exploit code with minimal human input. This lowers the barrier to entry for less-skilled attackers and increases the speed and sophistication of attacks, posing a significant threat to traditional security defenses. Not only are vulnerabilities increasing, but the ability to exploit them is becoming easier.
LLMs Introduce Dangerous Levels of Common Security Vulnerabilities
To evaluate the security properties of LLM-generated code, Veracode designed a set of 80 code completion tasks with known potential for security vulnerabilities according to the MITRE Common Weakness Enumeration (CWE) system, a standard classification of software weaknesses that can turn into vulnerabilities. The tasks prompted more than 100 LLMs to auto-complete a block of code in a secure or insecure manner, which the research team then analyzed using Veracode Static Analysis. In 45 percent of all test cases, LLMs introduced vulnerabilities classified within the OWASP (Open Web Application Security Project) Top 10—the most critical web application security risks.
Veracode found Java to be the riskiest language for AI code generation, with a security failure rate over 70 percent. Other major languages, like Python, C#, and JavaScript, still presented significant risk, with failure rates between 38 percent and 45 percent. The research also revealed LLMs failed to secure code against cross-site scripting (CWE-80) and log injection (CWE-117) in 86 percent and 88 percent of cases, respectively.
“Despite the advances in AI-assisted development, it is clear security hasn’t kept pace,” Wessling said. “Our research shows models are getting better at coding accurately but are not improving at security. We also found larger models do not perform significantly better than smaller models, suggesting this is a systemic issue rather than an LLM scaling problem.”
Managing Application Risks in the AI Era
While GenAI development practices like vibe coding accelerate productivity, they also amplify risks. Veracode emphasizes that organizations need a comprehensive risk management program that prevents vulnerabilities before they reach production—by integrating code quality checks and automated fixes directly into the development workflow.
As organizations increasingly leverage AI-powered development, Veracode recommends taking the following proactive measures to ensure security:
- Integrate AI-powered tools like Veracode Fix into developer workflows to remediate security risks in real time.
- Leverage Static Analysis to detect flaws early and automatically, preventing vulnerable code from advancing through development pipelines.
- Embed security in agentic workflows to automate policy compliance and ensure AI agents enforce secure coding standards.
- Use Software Composition Analysis(SCA) to ensure AI-generated code does not introduce vulnerabilities from third-party dependencies and open-source components.
- Adopt bespoke AI-driven remediation guidance to empower developers with precise fix instructions and train them to use the recommendations effectively.
- Deploy a Package Firewall to automatically detect and block malicious packages, vulnerabilities, and policy violations.
“AI coding assistants and agentic workflows represent the future of software development, and they will continue to evolve at a rapid pace,” Wessling concluded. “The challenge facing every organization is ensuring security evolves alongside these new capabilities. Security cannot be an afterthought if we want to prevent the accumulation of massive security debt.”
The complete 2025 GenAI Code Security Report is available to download on the Veracode website.
About Veracode
Veracode is a global leader in Application Risk Management for the AI era. Powered by trillions of lines of code scans and a proprietary AI-assisted remediation engine, the Veracode platform is trusted by organizations worldwide to build and maintain secure software from code creation to cloud deployment. Thousands of the world’s leading development and security teams use Veracode every second of every day to get accurate, actionable visibility of exploitable risk, achieve real-time vulnerability remediation, and reduce their security debt at scale. Veracode is a multi-award-winning company offering capabilities to secure the entire software development life cycle, including Veracode Fix, Static Analysis, Dynamic Analysis, Software Composition Analysis, Container Security, Application Security Posture Management, Malicious Package Detection, and Penetration Testing.
Learn more at www.veracode.com, on the Veracode blog, and on LinkedIn and X.
Copyright © 2025 Veracode, Inc. All rights reserved. Veracode is a registered trademark of Veracode, Inc. in the United States and may be registered in certain other jurisdictions. All other product names, brands or logos belong to their respective holders. All other trademarks cited herein are property of their respective owners.
View source version on businesswire.com: https://www.businesswire.com/news/home/20250730694951/en/
Contacts
Press and Media:
Katy Gwilliam
Head of Global Communications, Veracode
kgwilliam@veracode.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Istituto Nazionale Tumori IRCCS Fondazione G. Pascale Selects MEVION S250-FIT ™ for Southern Italy’s First Proton Therapy Center17.5.2026 09:00:00 EEST | Press release
Mevion Medical Systems, the global leader in compact proton therapy, today announced that it has been selected to deliver the MEVION S250-FIT Proton Therapy System™ to Istituto Nazionale Tumori IRCCS Fondazione G. Pascale in Naples. The award, made following a competitive European tender, will establish the first proton therapy center in Southern Italy, significantly expanding access to advanced radiation therapy for patients across the region and reducing the need for patients to travel long distances to northern Italy for care. Until now, proton therapy in Italy has only been available at centers located in Northern Italy, requiring patients from Southern Italy to travel significant distances for care. The Pascale project supports a broader strategy to establish Naples as a leading oncology hub and to improve healthcare equity across Italy. “The selection of the MEVION S250-FIT reflects our commitment to bringing advanced, accessible cancer care to patients in Southern Italy,” said D
TetraMem Announces 22nm Multi-Level RRAM Analog In-Memory Computing SoC Milestone16.5.2026 11:43:00 EEST | Press release
TetraMem Inc., a Silicon Valley–based semiconductor company developing analog in-memory computing (IMC) solutions, today announced the successful tape-out, manufacturing, and initial silicon validation of its MLX200 platform, a 22nm multi-level RRAM-based analog IMC system-on-chip (SoC). This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260516556464/en/ Photograph of the MLX200 chip with a five-cent coin for size reference The achievement marks a significant step toward the commercialization of analog computing architectures based on emerging non-volatile memory technologies, addressing the growing challenges of data movement, power consumption, and thermal constraints in modern AI systems. As AI workloads continue to scale, system performance is increasingly constrained by the cost of moving data between memory and compute units. Analog in-memory computing offers a fundamentally different approach by performing computation dir
NTT DATA Announces Intent to Acquire WinWire to Scale Enterprise AI Adoption and Accelerate Industry Transformation with Microsoft15.5.2026 19:36:00 EEST | Press release
NTT DATA, a global leader in AI, digital business and IT services, today announced it has signed a definitive agreement to acquire WinWire,an award-winning Microsoft partner specializing in Agentic AI, AI on Azure, data engineering and cloud-native development as foundational capabilities for enterprise AI. The acquisition strengthens NTT DATA’s position as a trusted partner to help organizations move beyond experimentation to operationalize AI at scale. The acquisition further advances NTT DATA’s enterprise AI strategy as demand accelerates for AI-driven, cloud-native transformation. By expanding capabilities across data platforms, agentic AI and modern applications, NTT DATA is sharpening its ability to deliver production-ready AI solutions aligned to industry needs, reinforcing its leadership as Microsoft’s Global System Integrator (GSI) Growth Champion Partner of the Year. Upon closing, WinWire will add more than 1,000 skilled Azure engineers and Microsoft specialists to NTT DATA,
STARTEEPO Invest Announces 5% Stake in Xerox Holdings Corporation15.5.2026 19:15:00 EEST | Press release
STARTEEPO Invest (“STARTEEPO”), an alternative investment fund focused on public equity opportunities, today announced that it has acquired a significant ownership position in Xerox Holdings Corporation (“Xerox” or the “Company”). This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260515594020/en/ As of the date of this release, STARTEEPO and its affiliates beneficially owns 6.6 million shares of Xerox (excluding options), representing approximately 5.05% of the Company’s outstanding common stock. STARTEEPO has filed a Schedule 13D with the U.S. Securities and Exchange Commission (the “SEC”) providing additional details regarding its investment. Investment Perspective STARTEEPO believes that Xerox represents an interesting investment opportunity supported by a combination of balance sheet initiatives, ongoing operational improvements, and its position within a changing and consolidating industry. In STARTEEPO’s view, the Company
NTT DATA Announces Intent to Acquire WinWire to Scale Enterprise AI Adoption and Accelerate Industry Transformation with Microsoft15.5.2026 17:00:00 EEST | Press release
NTT DATA, a global leader in AI, digital business and IT services, today announced it has signed a definitive agreement to acquire WinWire,an award-winning Microsoft partner specializing in Agentic AI, AI on Azure, data engineering and cloud-native development as foundational capabilities for enterprise AI. The acquisition strengthens NTT DATA’s position as a trusted partner to help organizations move beyond experimentation to operationalize AI at scale. The acquisition further advances NTT DATA’s enterprise AI strategy as demand accelerates for AI-driven, cloud-native transformation. By expanding capabilities across data platforms, agentic AI and modern applications, NTT DATA is sharpening its ability to deliver production-ready AI solutions aligned to industry needs, reinforcing its leadership as Microsoft’s Global System Integrator (GSI) Growth Champion Partner of the Year. Upon closing, WinWire will add more than 1,000 skilled Azure engineers and Microsoft specialists to NTT DATA,
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom