Uppsats

Vulnerabilities in AI-generated Web Applications : An Analysis of Common Vulnerabilities in Web Applications Created by Non-Technical Prompting of ChatGPT-5 and Claude Sonnet 4.5

Kandidat-uppsats

KTH/Skolan för elektroteknik och datavetenskap (EECS)

Publicerad: 2026

Språk: Engelska

Sammanfattning

Artificial intelligence (AI) has seen a big increase in popularity due to the improvement and general availability of large language models (LLMs) such as ChatGPT and Claude. LLMs have granted people without programming experience the ability to generate complete web applications with a single prompt. When an LLM creates an entire web application for a person who cannot understand the code generated, it is critical that the person knows what to expect of the application’s state of security. This study attempts to provide that knowledge by analysing AI-generated web applications in terms of common web application security issues, assessing the prevalence and severity of discovered vulnerabilities. Due to the hasty advancement of AI, there is currently a deficit of studies analysing the security of AI-generated web applications, a deficit that this study attempts to reduce. The LLMs ChatGPT-5 and Claude Sonnet 4.5 were queried for complete web applications in several isolated conversations. A standardised ”prompting script” was created and used for each conversation, ensuring reproducibility across the web application generations. Furthermore, it ensured that the prompts were written as if by a person without any programming experience asking for a complete web application solution. For each generated web application, a vulnerability assessment was made using a custom suite of automated scanners focusing on the top three vulnerabilities of the OWASP Top 10 (2021), summarising the prevalence and severity of discovered vulnerabilities. The results showed that web applications created by non-technical prompting of LLMs exhibit multiple recurring vulnerabilities categorised as A01- Broken Access Control and A03-Injection. Furthermore, the majority of the vulnerabilities have CVSS scores of the Medium or High category. The reliability of the results would be improved by analysing additional web applications and performing manual penetration testing for verifying the output of the automated scanners, making the study a good stepping stone to further research. This study provides a basis for advising people without programming experience to be wary of the demonstrated risks of having an LLM create complete web application solutions.

Information

Författare
Löfgren, Nils
Lärosäte / institution
KTH/Skolan för elektroteknik och datavetenskap (EECS)
Publiceringsdatum
2026
Uppsatstyp
Kandidat-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.