logo

Wiz Research Uncovers Critical Vulnerability in AI Vibe Coding platform Base44 Allowing Unauthorized Access to Private Applications

ID: 2c7f774a-9318-5c2f-b520-0e6d18ddcfd3

STIX ID: report--2c7f774a-9318-5c2f-b520-0e6d18ddcfd3

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2025-07-29

Date Updated: 2026-05-01

...
...

Wiz Research disclosed a critical authentication vulnerability in Base44 (now part of Wix) where unauthenticated registration and OTP verification APIs accepted publicly visible app_id values, allowing attackers to create verified accounts for private applications and bypass SSO, potentially exposing sensitive enterprise data; the issue was responsibly disclosed, fixed within 24 hours, and no evidence of exploitation was found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.