Research · curated 25 Jul 2026

Security Vulnerability Patterns in AI-Generated Code: A Cross-Model Comparative Study

Coverage timeline

25 Jul 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

AI-generated automation scripts written by non-expert office workers routinely carry exploitable vulnerabilities and often enter enterprise workflows without security review, expanding organizational attack surface.

A cross-model comparative study by Kahn and Hastings generated nine Python automation scripts using identical prompts across ChatGPT, Microsoft Copilot, and Google Gemini, then used Claude Code to perform a standardized vulnerability review scored with CVSS v3.1 and mapped to OWASP Top 10 and MITRE ATT&CK. Every script contained exploitable vulnerabilities, with nine of 17 vulnerability classes appearing across all three models and weighted CVSS scores differing by less than 10%, indicating risk is tied to task category rather than a specific model.