2025 GenAI Code Security Report

October 2025 Update
Report Cover

Generative AI is reshaping software development, yet its impact on code security remains largely overlooked. This report assesses over 100 large language models (LLMs) across four major programming languages—Java, JavaScript, Python, and C#—to determine how often AI-generated code is secure by default. Findings reveal that only 55% of generated code avoids common vulnerabilities, with no significant improvements tied to model size or recency.

Report Snapshot

Through rigorous testing against four critical CWE categories—SQL Injection, Cross-Site Scripting, Log Injection, and Weak Cryptographic Algorithms—the research highlights systemic gaps in AI coding tools. While LLMs excel at producing functional, syntactically correct code, they frequently miss security best practices unless explicitly guided. This report provides valuable insights for organizations adopting AI-driven development, underlining the need for proactive security measures and developer oversight.

RECAPTCHA

By clicking below you agree to our privacy policy, confirm that you are over the age of 16, and that Insights for Professionals can contact you for marketing purposes via email, social, digital ads, post and telephone.