Vulnerability Analysis in Vibe Coding for Web Applications: A Case Study
DOI:
https://doi.org/10.70577/asce.v5i3.805Keywords:
vibe coding; web application security; white-box audit; OWASP Top 10:2025; AI-generated code; case study.Abstract
Vibe coding, a term coined in 2025, describes a way of programming in which the developer hands over much of the code production to a language model through natural-language instructions. Recent scholarship has mostly looked at its effects on productivity and accessibility; the security of artifacts actually deployed in production has received far less attention. This article reports on a single case study: a white-box security audit of a multi-tenant SaaS application built entirely through vibe coding with Claude Sonnet 4.6. The master prompt delegated security decisions to the model, within the functional constraints the prompt itself established. The audit combined reconnaissance, static source-code analysis, live probing of the deployed application, and manual false-positive verification, following the OWASP Web Security Testing Guide. A second language model served as an audit copilot throughout. All 41 confirmed findings were mapped to the OWASP Top 10:2025. In this particular case, 39.0% clustered in just two categories Security Misconfiguration (A02) and Authentication Failures (A07) though these results are specific to the case examined and are not intended to generalize beyond it. The AI-assisted inspection also produced a 10.9% false-positive rate, which points to the practical value of including a systematic human-verification step in audits of this kind. A possible bias is acknowledged: the auditor model (Claude Opus 4.7) belongs to the same family as the generator (Claude Sonnet 4.6). In the case analyzed, generic security instructions did not prevent the documented findings even when the model was warned about a subsequent audit. Directions for future research are also proposed.
Downloads
References
Ambati, S. H. (2023). Security and Authenticity of AI-generated code [Master of Science thesis]. University of Saskatchewan, Department of Computer Science.
Biryukov, A., Dinu, D., & Khovratovich, D. (2016). Argon2: the memory-hard function for password hashing and other applications. 2016 IEEE European Symposium on Security and Privacy (EuroS&P). DOI: https://doi.org/10.1109/EuroSP.2016.31
Domínguez Chávez, J. (2025). Análisis Crítico de ChatGPT y sus Aplicaciones. [revista por confirmar — disponible en ResearchGate].
Gadde, A. (2025). Democratizing Software Engineering through Generative AI and Vibe Coding: The Evolution of No-Code Development. Journal of Computer Science and Technology Studies, 7(4), 556-572. https://doi.org/10.32996/jcsts.2025.7.4.66 DOI: https://doi.org/10.32996/jcsts.2025.7.4.66
Garcia Berzosa, H. (2024). Seguridad y privacidad: ¿cómo valorar la seguridad sobre un sistema basado en IA? [Trabajo Fin de Máster (Máster Universitario en Ciberseguridad y Privacidad, Área M1.886 Privacidad)]. Universitat Oberta de Catalunya.
Geng, F., Shah, A., Li, H., Mulla, N., Swanson, S., Raj, G. S., Zingaro, D., & Porter, L. (2025). Exploring Student-AI Interactions in Vibe Coding. arXiv preprint arXiv:2507.22614. https://arxiv.org/abs/2507.22614
Jones, M., Bradley, J., & Sakimura, N. (2015). JSON Web Token (JWT) (RFC 7519). Internet Engineering Task Force. https://www.rfc-editor.org/rfc/rfc7519 DOI: https://doi.org/10.17487/RFC7519
Karpathy, A. (2025). There’s a new kind of coding I call «vibe coding». Publicación en X/Twitter, 2 de febrero de 2025.
Mahiques Fenollar, M. (2025). Desarrollo de una aplicación web full-stack para pruebas regresivas mediante una metodología de programación asistida por IA: Análisis comparativo con el desarrollo tradicional [Trabajo Fin de Grado (Grado en Ingeniería Informática)]. Universitat Politècnica de València, Escuela Politécnica Superior de Alcoy.
Meske, C., Hermanns, T., Weiden, E. von der, Loser, K.-U., & Berger, T. (2025). Vibe Coding as a Reconfiguration of Intent Mediation in Software Development: Definition, Implications, and Research Agenda. arXiv preprint arXiv:2507.21928. https://arxiv.org/abs/2507.21928 DOI: https://doi.org/10.2139/ssrn.5378201
Mohsin, A., Janicke, H., Wood, A., Sarker, I. H., Maglaras, L., & Janjua, N. (2024). Can We Trust Large Language Models Generated Code? A Framework for In-Context Learning, Security Patterns, and Code Evaluations Across Diverse LLMs. arXiv preprint arXiv:2406.12513. https://arxiv.org/abs/2406.12513
Moore, J. H., & Tatonetti, N. (2025). Vibe coding: a new paradigm for biomedical software development. BioData Mining, 18(46). https://doi.org/10.1186/s13040-025-00462-9 DOI: https://doi.org/10.1186/s13040-025-00462-9
OWASP Foundation. (2020). Web Security Testing Guide v4.2. OWASP Foundation.
OWASP Foundation. (2025). OWASP Top 10:2025. https://owasp.org/Top10/2025/
Páez Poblete, E. R. (2024). Aplicación de herramientas para el análisis estático y dinámico de código en aplicaciones web [Trabajo Final (Tecnicatura Universitaria en Programación Web)]. Universidad Nacional de San Juan, Facultad de Ciencias Exactas, Físicas y Naturales, Departamento de Informática.
Pramudia, A., Suhartana, M., & Hassan, R. (2025). Simulation Vulnerabilities Web Application using Top 10 OWASP Approach. Asia-Pacific Journal of Information Technology and Multimedia (APJITM), 14(2), 595-605. https://doi.org/10.17576/apjitm-2025-1402-16 DOI: https://doi.org/10.17576/apjitm-2025-1402-16
Ray, P. P. (2025). A Review on Vibe Coding: Fundamentals, State-of-the-art, Challenges and Future Directions. TechRxiv preprint. https://doi.org/10.36227/techrxiv.175475402.27450434 DOI: https://doi.org/10.36227/techrxiv.174681482.27435614/v1
Sarkar, A., & Drosos, I. (2025). Vibe coding: programming through conversation with artificial intelligence. arXiv preprint arXiv:2506.23253. https://arxiv.org/abs/2506.23253
Wang, J., Cao, L., Luo, X., Zhou, Z., Xie, J., Jatowt, A., & Cai, Y. (2024, abril). Enhancing Large Language Models for Secure Code Generation: A Dataset-driven Study on Vulnerability Mitigation. Proceedings of the 46th International Conference on Software Engineering (ICSE ’24). https://arxiv.org/abs/2310.16263
Yin, R. K. (2018). Case Study Research and Applications: Design and Methods (6.ª ed.). SAGE Publications.
Material suplementario
El material suplementario (prompt maestro, listado completo de hallazgos y comparación de stack) y el código fuente del sistema auditado están disponibles en: https://github.com/danilogalloec/cashflow-nlp
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Danilo Marcelo Gallo Colcha, Fátima Avilés Castillo.

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
Eres libre de:
- Compartir : copiar y redistribuir el material en cualquier medio o formato
- Adaptar : remezclar, transformar y desarrollar el material
- El licenciante no puede revocar estas libertades siempre y cuando usted cumpla con los términos de la licencia.
En los siguientes términos:
- Atribución : Debe otorgar el crédito correspondiente , proporcionar un enlace a la licencia e indicar si se realizaron cambios . Puede hacerlo de cualquier manera razonable, pero no de ninguna manera que sugiera que el licenciante lo respalda a usted o a su uso.
- No comercial : no puede utilizar el material con fines comerciales .
- CompartirIgual — Si remezcla, transforma o construye sobre el material, debe distribuir sus contribuciones bajo la misma licencia que el original.
- Sin restricciones adicionales : no puede aplicar términos legales ni medidas tecnológicas que restrinjan legalmente a otros hacer algo que la licencia permite.














