Hacker News new | ask | show | jobs
by Retr0id 321 days ago
From my (limited) experience poking at vibecoded apps, "broken/missing authentication" is the most common issue by far.

That said, the 2021 OWASP Top 10 had "broken access control" in the top spot already, prior to the real takeoff of vibecoding: https://owasp.org/www-project-top-ten/ - curious to see the 2025 update.