Six in January, 15 in February, 35 in March. These are not estimates of risk, they are counted vulnerabilities traced back to the commit that introduced them.

Key takeaways

  • The Vibe Security Radar project, run by the Systems Software and Security Lab at Georgia Tech, tracks CVEs directly introduced by AI-generated code. It recorded 6 CVEs in January 2026, 15.
  • 124 live listings in this category publish a rate, at a median top-of-range of $100 an hour and a ceiling of $300.
  • The work is remote contract work, asynchronous, with no set hours and no guaranteed volume.
  • Applications screen on a short skills assessment rather than a resume or interview.

What was reported

The finding

The Vibe Security Radar project, run by the Systems Software and Security Lab at Georgia Tech, tracks CVEs directly introduced by AI-generated code. It recorded 6 CVEs in January 2026, 15 in February and 35 in March. Researcher Hanqing Zhao's methodology pulls from CVE.org, the National Vulnerability Database, the GitHub Advisory Database and OSV, then traces each CVE's fixing commit back through Git history using AI agents to assess whether AI coding tools introduced the vulnerable code. Researchers estimate the true count is five to ten times higher across the broader open-source ecosystem.

The Georgia Tech methodology is what makes the number credible. It pulls from CVE.org, the National Vulnerability Database, the GitHub Advisory Database and OSV, then walks each CVE's fixing commit back through Git history to assess whether an AI coding tool wrote the vulnerable code. The researchers say the true figure across the open-source ecosystem is likely five to ten times higher.

What the listings pay

Set that beside Veracode's finding that AI-generated code carries 2.74 times more vulnerabilities than human-written code, and you have a measured problem growing month over month rather than a speculative one.

#RoleAdvertised ratePlatform
1CUDA Engineering Expert$300 to $300 an hourMercor
2Cybersecurity Research Expert, Offensive Security & Vulnerability Research$200 to $250 an hourMercor
3Machine Learning Engineer Talent Network$70 to $250 an hourMercor
4Legacy Codebase Migration Expert$200 to $200 an hourMercor
5UK-Based Data Engineering Experts$140 to $200 an hourMercor
6AI Software Engineering Domain Expert$100 to $200 an hourmicro1
7AI/ML Engineer$70 to $200 an hourmicro1
8Engineering / Platform Professionals$80 to $160 an hourMercor
9Open Source Applied Engineer Talent Network$100 to $150 an hourMercor
10Backend Engineer Talent Network$70 to $150 an hourMercor

Source: 124 live listings on this board that publish a rate, read directly from each posting on 2026-09-06. Listings without a published rate are excluded rather than estimated.

CVEs Traced to AI-Written Code Went From 6 to 35 in Three Months

How this compares across the board

A rate only means something next to the alternatives. This is every category we track with at least five listings publishing a rate, ranked by median top-of-range, so you can see where this work sits rather than taking a single number on trust.

CategoryListingsMedian lowMedian topHighest
Legal95$100$140$400
Medical68$77$120$400
Consulting45$80$120$280
Finance94$80$110$280
Engineering114$70$100$300
Research/PhD132$70$90$280
Writing36$40$80$280
Bilingual78$44$52$120
Annotation25$12$24$120

Same source and date as above. Categories are matched on listing title, so a role can appear in more than one.

What it means for you

Which is why code evaluation is a durable category. Across 124 live engineering and code listings on our board that publish a rate, the median top-of-range is $100 an hour, reaching $300. See code evaluation roles.

Who should apply

Two checks before you spend time on an application. Confirm the role accepts applicants from your country with the eligibility checker, since a meaningful share of listings carry location requirements. Then run the advertised rate through the take-home calculator, because this is contract work and the headline figure is before self-employment tax.

Applications complete on the hiring platform and usually take a few minutes, with a short skills assessment in place of an interview. Fill in every credential, language and professional background field on your profile. Those are what route you to the better paid listings, and most applicants leave them blank.

Frequently asked questions

How fast are AI-code CVEs growing?

Georgia Tech's tracker recorded 6 in January 2026, 15 in February and 35 in March, all traced directly to AI-generated code.

How do researchers know AI wrote the code?

They trace each CVE's fixing commit back through Git history using AI agents, drawing on CVE.org, the National Vulnerability Database, the GitHub Advisory Database and OSV.

Is the real number higher?

Researchers estimate the true count across the broader open-source ecosystem is five to ten times higher than what the tracker captures.

What does code review work pay?

Across 124 live engineering and code listings publishing a rate, the median top-of-range is $100 an hour, reaching $300.

Do I need a security background?

Helpful but not usually required. Most listings want strong engineers who read unfamiliar code carefully and can explain precisely why something is wrong.

Sources

  1. Georgia Tech Research, Bad vibes: AI-generated code is vulnerable, researchers warn
  2. Infosecurity Magazine, Researchers sound the alarm on vulnerabilities in AI-generated code
  3. Cloud Security Alliance, Vibe coding's security debt: the AI-generated CVE surge

See every live role

The full board updates several times a week, with the advertised rate on each listing and closed roles removed.

Browse all AI jobs