Threat · curated 17 Jul 2026
Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44
First reported wiz.io
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Base44's flaw shows that AI-powered app-building platforms can expose all private applications and data through a trivial parameter-based auth bypass, making them a high-value target for attackers seeking access to sensitive customer-built systems.
Wiz disclosed a now-patched critical authentication bypass in Base44, an AI-powered 'vibe coding' platform owned by Wix, where supplying only a non-secret 'app_id' value to undocumented registration and email-verification endpoints let an attacker create a verified account for private applications. The flaw bypassed all authentication controls, including SSO, granting full access to private apps and their data; Wix fixed it within 24 hours of the July 9, 2025 disclosure, with no evidence of exploitation in the wild.