Skip to main content
Lornets

Evidence note

Security Vulnerabilities in AI-Generated Code: A Large-Scale Analysis of Public GitHub Repositories

Peer-Reviewed Research2026

What was examined?

An empirical security analysis of public GitHub files explicitly attributed to several AI code-generation tools.

CodeQL-based analysis of files attributed to ChatGPT, GitHub Copilot, Amazon CodeWhisperer and Tabnine.

7,703 files; 4,241 detected CWE instances; 77 vulnerability types.

Key findings

  1. 01Material CWE-mapped weaknesses were identified in the dataset.
  2. 0287.9% of the analysed AI-attributed files had no CWE-mapped vulnerability detected under the study methodology.
  3. 03Vulnerability patterns varied by programming language.
  4. 04The dataset was heavily dominated by ChatGPT-attributed files.

Why it matters. Lornets interpretation.

The evidence supports neither 'AI code is safe' nor 'AI code is inherently insecure'. Security should be established from the actual application context, controls and verification evidence.

This is the Lornets reading of the source, not a finding of the source itself.

What it does not establish

  1. 01A lack of a CodeQL-detected CWE does not establish that a file or application is secure.
  2. 02Static analysis does not identify every security weakness.
  3. 0391.52% of the collected files were ChatGPT-attributed, limiting equal comparison between tools.
  4. 04The result must not be presented as '87.9% of AI code is secure'.

Source

Evidence type
Peer-Reviewed Research
Published
2026
Status
Current

Read the original research

Relevant Lornets framework areas

Framework domains

  • Security & Access Control
  • Architecture & Maintainability

Related evidence

Government Guidance

2022

NIST Secure Software Development Framework v1.1

National Institute of Standards and Technology, SP 800-218, SSDF v1.1

SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.

  • Security & Supply Chain
  • Software Quality & Maintainability

Current, revision underway

Read Evidence Note

Source record

Published
2026
Last verified
2026-08-11
Source status
Current