μ λͺ©(νκΈ): AI μμ± μ½λ 보μ μ·¨μ½μ νμ€ν μλ¬Έ μ λͺ©(μλ¬Έ): I Built a Security Scanner for AI-Generated Code β Then Found Vulnerabilities in My Own Projects What happens when you run your own tool on your own code μλ¬Έ: I Built a Security Scanner for AI-Generated Code β Then Found Vulnerabilities in My Own Projects What happens when you run your own tool on your own code μμ€: dev-to-vibecoding MD νμΌ: content/2026-05-26/dev-to-vibecoding-i-built-a-security-scanner-for-ai-generated-code-t.md
ν΅μ¬ λ΄μ©
AI μ½λ 보μ μ€μΊλλ₯Ό λ§λ κ°λ°μκ° μκΈ° νλ‘μ νΈμμ μ·¨μ½μ 4κ°λ₯Ό μ§μ μ°Ύμμ΄μ.
μλ¬Έμ λ°λ₯΄λ©΄ AI μμ± μ½λμ 45%μμ OWASP Top 10 μ·¨μ½μ μ΄ λ°κ²¬λκ³ , 1,400κ°+ μ± λΆμμμ 65%κ° λ³΄μ μ΄μλ₯Ό κ°μ‘μ΄μ. 2026λ 3μ ν λ¬μλ§ AI μμ± μ½λ κ΄λ ¨ CVEλ 35건 λ³΄κ³ λκ±°λ μ.
μ€μ λ°κ²¬ ν¨ν΄μ νλμ½λ©λ API ν€, λΉνμ±νλ Supabase RLS, μ‘΄μ¬νμ§ μλ npm ν¨ν€μ§, μμΌλμΉ΄λ CORS, λμ eval() νΈμΆμ΄μμ΄μ. λ³ΈμΈ λΌμ΄λΈ μλΉμ€μμλ νλ‘ νΈμλ eval() XSS μν 3건과 Flask λ°±μλ μμΌλμΉ΄λ CORS 1κ±΄μ΄ λμμ΄μ.
μλ μ€μ¬μ AI κ°λ°μΌμλ‘ λ°°ν¬ μ μλ 보μ μ€μΊμ΄ κΈ°λ³Έ 곡μ μ΄ λμ΄μΌ νλ€λ μ νΈμμ.
μ‘λμ€μ νλ§λ
μ€μλΉμ€μμλ eval() XSS 3건과 μμΌλμΉ΄λ CORS 1κ±΄μ΄ λ°κ²¬λμ΄μ. μμ± μλλ³΄λ€ μ€μΊ μλνκ° λ¨Όμ μμ.