Security Study: Every AI Coding Tool Tested Introduced SSRF — Zero Built CSRF or Security Headers
Awesome Agents·high signal
A new study tested 5 major AI coding tools by building 3 identical apps per tool and found 69 vulnerabilities across all 15 apps; every single tool introduced Server-Side Request Forgery, zero apps implemented CSRF protection, and zero set security headers. Carnegie Mellon data adds context: 61% of AI-generated code is functionally correct but only 10.5% is secure. This is a different study from the 318-vulnerability audit from March 11 — this one isolates tool-specific failure patterns.