Sygnia Penetration Test Reveals Critical “vibe coded” Vulnerabilities Within Claude-Based Application
Leading incident response team launches AI Cybersecurity Services in wake of rising AI-assisted code development.
Sygnia, the world’s foremost incident response and cyber readiness team, revealed critical vulnerabilities following a penetration test of a customer onboarding application, developed in Claude, that processed highly sensitive personal and financial information, including government-issued identification, identity verification data, and payment details. Identified by an LLM, the vulnerability enabled low-access privilege users to see critical client personal identification information by not requiring appropriate user verification before issuing or restoring applicant access tokens.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260728834521/en/ LLM analysis highlighting a high-severity vulnerability within a “vibe-coded” application.
Investigation findings highlighted a flaw with access token issuance and restoration, where possession of an applicant GUID was treated as sufficient proof to issue an access token. The reason for this flaw was tied to the AI-assisted implementation strategy which featured access tokens, expiration, rate limiting, and logging, but missed the critical pre-issuance question to validate whether the requester is entitled to receive or restore an applicant token.








