Wiz Discovers Major Access Bypass Vulnerability in Base44’s AI-Driven Coding Platform
July 29, 2025
In a significant security revelation, cybersecurity experts from Wiz have exposed a critical vulnerability in Base44, a widely-used coding platform featuring AI capabilities. This flaw poses serious risks, as it enables unauthorized users to access private applications developed by other users on the platform.
The specific vulnerability allows attackers to bypass authentication controls effortlessly. Wiz’s report details that an intruder merely needed to submit a non-sensitive ‘app_id’ to undocumented registration and email verification endpoints, which could lead to the creation of a verified account. Such unauthorized access effectively nullifies safeguards such as Single Sign-On (SSO), thereby granting complete entry to sensitive applications and the data within.
Base44, owned by Wix, received the disclosure on July 9, 2025, and took immediate action, issuing a comprehensive fix within 24 hours. Fortunately, at this time, there is no evidence that this vulnerability was exploited in the wild, suggesting that the breach remains theoretical rather than realized.
Cybersecurity consciousness is critical in a landscape where vulnerabilities can significantly impact business operations and sensitive data integrity. For organizations utilizing platforms like Base44, vigilance regarding potential security pitfalls is paramount. The nature of this vulnerability underscores the importance of robust authentication mechanisms and continuous monitoring of system protections.
From a technical perspective, the attack aligns with tactics outlined in the MITRE ATT&CK framework, particularly in respects to initial access and privilege escalation. Attackers could exploit such weaknesses at the entry point, using legitimate access mechanisms to gain broader privileges within the affected systems.
As the repercussions of this vulnerability resonate, business owners and tech professionals are reminded of the necessity for proactive cybersecurity measures. Employing comprehensive monitoring solutions and keeping authentication protocols up to date can mitigate the risks posed by similar flaws in the future.
This incident serves as a crucial reminder of the ongoing challenges in maintaining secure digital environments, especially in platforms that enable collaborative coding and application development. The rapid response from Wix highlights the importance of responsible disclosure practices, emphasizing the role that collaboration plays in enhancing cybersecurity frameworks.