mimile
Back to feed

Georgia Tech reports 35 CVEs from AI-generated code in March

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Georgia Tech reports 35 CVEs from AI-generated code in March

Georgia Tech researchers reported 35 new CVEs disclosed in March 2026 that they attribute directly to AI-generated code. The count is up from six in January and 15 in February, the Vibe Security Radar project showed.

Key Facts

  • At least 35 new CVE entries were disclosed in March 2026 as a direct result of AI-generated code, up from six in January and 15 in February.
  • The Vibe Security Radar project, started in May 2025 by Georgia Tech's Systems Software & Security Lab, tracks vulnerabilities introduced by AI coding tools.
  • Researchers track approximately 50 AI-assisted coding tools, including Claude Code, GitHub Copilot, Cursor, Devin, Windsurf, Aider, Amazon Q and Google Jules.
  • Among 74 confirmed CVEs directly linked to AI coding tools, Claude Code appeared most often.
  • Hanqing Zhao, founder of the Vibe Security Radar, said the real number of AI-linked CVEs is 'almost certainly higher' than the dashboard shows.

Vibe Security Radar Project

The Vibe Security Radar was started in May 2025 by the Systems Software & Security Lab at Georgia Tech’s School of Cybersecurity and Privacy. The project tracks vulnerabilities directly introduced by AI coding tools that made it into public advisories such as CVE.org, the US National Vulnerability Database, GitHub Advisory Database, Open Source Vulnerabilities and RustSec. Hanqing Zhao, founder of the project, said the goal is to produce real numbers rather than benchmarks or hypotheticals.

Tracking Methodology

Researchers pull data from public vulnerability databases, find the commit that fixed each flaw, and trace backwards to identify who introduced the bug. When a commit carries an AI tool signature such as a co-author tag or bot email, the team flags it. AI agents then examine the actual Git repository and commit history to determine whether AI-generated code contributed to each vulnerability. The project covers approximately 50 AI-assisted coding tools, including Claude Code, GitHub Copilot, Cursor, Devin, Windsurf, Aider, Amazon Q and Google Jules.

Claude Code and Attribution Bias

Among 74 confirmed CVEs directly attributable to AI coding tools, Claude Code appeared most frequently. Zhao noted that the Anthropic tool always leaves a signature, while Copilot’s inline suggestions leave no trace at all. Zhao said the real number of CVEs caused by AI coding tools is 'almost certainly higher' than the dashboard shows, particularly for open-source projects.

1 source

Georgia Tech reports 35 CVEs from AI-generated code in March