Wiz Identifies Critical Access Bypass Vulnerability in AI-Driven Base44 Coding Platform

July 29, 2025
LLM Security / Vulnerability

Cybersecurity researchers have revealed a recently patched critical security vulnerability in the popular AI-driven coding platform Base44. This flaw could enable unauthorized access to private applications created by its users. According to a report from cloud security firm Wiz, the vulnerability was alarmingly easy to exploit; an attacker merely needed to provide a non-secret ‘app_id’ at undocumented registration and email verification endpoints to create a verified account for private applications. This breach effectively bypassed all authentication mechanisms, including Single Sign-On (SSO) protections, granting full access to sensitive applications and data. Following responsible disclosure on July 9, 2025, Wix, the company that owns Base44, implemented an official fix within 24 hours. Fortunately, there is no evidence that this vulnerability was ever maliciously exploited in practice.

Wiz Discovers Major Access Bypass Vulnerability in Base44’s AI-Driven Coding Platform

July 29, 2025

In a significant security revelation, cybersecurity experts from Wiz have exposed a critical vulnerability in Base44, a widely-used coding platform featuring AI capabilities. This flaw poses serious risks, as it enables unauthorized users to access private applications developed by other users on the platform.

The specific vulnerability allows attackers to bypass authentication controls effortlessly. Wiz’s report details that an intruder merely needed to submit a non-sensitive ‘app_id’ to undocumented registration and email verification endpoints, which could lead to the creation of a verified account. Such unauthorized access effectively nullifies safeguards such as Single Sign-On (SSO), thereby granting complete entry to sensitive applications and the data within.

Base44, owned by Wix, received the disclosure on July 9, 2025, and took immediate action, issuing a comprehensive fix within 24 hours. Fortunately, at this time, there is no evidence that this vulnerability was exploited in the wild, suggesting that the breach remains theoretical rather than realized.

Cybersecurity consciousness is critical in a landscape where vulnerabilities can significantly impact business operations and sensitive data integrity. For organizations utilizing platforms like Base44, vigilance regarding potential security pitfalls is paramount. The nature of this vulnerability underscores the importance of robust authentication mechanisms and continuous monitoring of system protections.

From a technical perspective, the attack aligns with tactics outlined in the MITRE ATT&CK framework, particularly in respects to initial access and privilege escalation. Attackers could exploit such weaknesses at the entry point, using legitimate access mechanisms to gain broader privileges within the affected systems.

As the repercussions of this vulnerability resonate, business owners and tech professionals are reminded of the necessity for proactive cybersecurity measures. Employing comprehensive monitoring solutions and keeping authentication protocols up to date can mitigate the risks posed by similar flaws in the future.

This incident serves as a crucial reminder of the ongoing challenges in maintaining secure digital environments, especially in platforms that enable collaborative coding and application development. The rapid response from Wix highlights the importance of responsible disclosure practices, emphasizing the role that collaboration plays in enhancing cybersecurity frameworks.

Source link