Things like this are usually a systemic failure rather than being 100% attribute to a single person.
There is a point of responsibility in here, and it is up to the management to triage the fallout of this "mistake".
Look at the date and re-evaluate.
I know I should have a better response than just maniacal laughter, but I really don't. This is what those of us who have not gone all-in on LLM coding have been saying... no matter how much it can write functional code, it still fails utterly at non-code concerns. In this case, security. It is insane that someone who worked on the product did not get that.