Wiz Identifies Critical Access Bypass Vulnerability in AI-Driven Base44 Coding Platform
July 29, 2025
LLM Security / Vulnerability
Cybersecurity researchers have revealed a recently patched critical security vulnerability in the popular AI-driven coding platform Base44. This flaw could enable unauthorized access to private applications created by its users. According to a report from cloud security firm Wiz, the vulnerability was alarmingly easy to exploit; an attacker merely needed to provide a non-secret ‘app_id’ at undocumented registration and email verification endpoints to create a verified account for private applications. This breach effectively bypassed all authentication mechanisms, including Single Sign-On (SSO) protections, granting full access to sensitive applications and data. Following responsible disclosure on July 9, 2025, Wix, the company that owns Base44, implemented an official fix within 24 hours. Fortunately, there is no evidence that this vulnerability was ever maliciously exploited in practice.
LLM Security / Vulnerability
Wiz Discovers Major Access Bypass Vulnerability in Base44’s AI-Driven Coding Platform July 29, 2025 In a significant security revelation, cybersecurity experts from Wiz have exposed a critical vulnerability in Base44, a widely-used coding platform featuring AI capabilities. This flaw poses serious risks, as it enables unauthorized users to access private…
Wiz Identifies Critical Access Bypass Vulnerability in AI-Driven Base44 Coding Platform
July 29, 2025
LLM Security / Vulnerability
Cybersecurity researchers have revealed a recently patched critical security vulnerability in the popular AI-driven coding platform Base44. This flaw could enable unauthorized access to private applications created by its users. According to a report from cloud security firm Wiz, the vulnerability was alarmingly easy to exploit; an attacker merely needed to provide a non-secret ‘app_id’ at undocumented registration and email verification endpoints to create a verified account for private applications. This breach effectively bypassed all authentication mechanisms, including Single Sign-On (SSO) protections, granting full access to sensitive applications and data. Following responsible disclosure on July 9, 2025, Wix, the company that owns Base44, implemented an official fix within 24 hours. Fortunately, there is no evidence that this vulnerability was ever maliciously exploited in practice.
