Critical Base44 Flaw Let Hackers Bypass Authentication Controls

Wix Quickly Patches Critical Base44 Flaw Allowing Unauthorized Access to Private Apps, Highlighting Ongoing AI Security Risks

  • Critical vulnerability in Base44 allowed unauthorized access to private apps with only a public app ID.
  • Wiz researchers found and reported the flaw, and Wix patched it within 24 hours.
  • The issue bypassed authentication and Single Sign-On, exposing users’ data.
  • No evidence exists that attackers exploited the bug before the fix.
  • Recent incidents highlight ongoing Cybersecurity risks in AI and large language model tools.

On July 29, 2025, researchers disclosed a serious security flaw in the AI-powered coding platform Base44, which is owned by Wix. The security firm Wiz identified and reported the vulnerability, which allowed people to gain access to private apps built by users without proper authorization.

- Advertisement -

The bug let attackers register and verify accounts on private apps using only the app’s public identifier, known as “app_id.” According to Wiz’s report, the flaw could be exploited via two registration endpoints that lacked proper security checks. “The vulnerability we discovered was remarkably simple to exploit — by providing only a non-secret app_id value to undocumented registration and email verification endpoints, an attacker could have created a verified account for private applications on their platform,” the researchers said. Wix responded by issuing a patch within 24 hours of notification on July 9, 2025.

The threat bypassed standard authentication such as Single Sign-On (SSO), putting all app data at risk. Wiz explained that since the app_id was visible in the app’s URL and files, anyone could use it to create and verify new accounts on private projects. “After confirming our email address, we could just login via the SSO within the application page, and successfully bypass the authentication,” said security researcher Gal Nagli. There is no evidence available that the flaw was actively exploited before it was fixed.

The incident exposes challenges as companies adopt AI-driven tools like “vibe coding.” These platforms allow users to create programs through natural language prompts, but new security issues may arise that traditional systems do not cover. Researchers have also warned of attacks on popular large language model (LLM) systems, such as prompt injection attacks, Gemini-ai-cli-hijack”>malicious code execution, phishing, and even leaking credentials.

Security teams are now exploring strategies like toxic flow analysis, which predicts potential attack scenarios in AI systems. Meanwhile, misconfigured servers in AI ecosystems, such as Model Control Protocol (MCP) servers, have been found exposed to the internet without authentication, risking data leaks and service abuse. According to Knostic, attackers could extract sensitive tokens and keys stored on these servers, gaining access to connected services.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Younghoon Kim Says XRP Could Beat Gold and Silver in 2026…

Younghoon Kim predicts XRP could outperform Gold and silver in 2026.XRP trades near $1.87...

Retail Extremely Bullish on American Bitcoin; Chatter Normal

Trump Media & Technology Group Corp. (DJT) closed at $13.77 on Friday and traded...

India Drives BRICS 2026: De-Dollarization, AI & Finance 2026

India begins its BRICS presidency with a 2026 theme centered on financial cooperation, technology...

US govt-tagged wallets monitored; $50 dust traces link today

A small Bitcoin transfer of 0.000571 BTC (about $52) was sent to a wallet...

Coinbase pauses peso fiat rails in Argentina keeps crypto…

Coinbase is pausing peso-based fiat services in Argentina and will stop ARS-to-USDC and local...
- Advertisement -

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Bitcoin (BTC) $ 91,102.00 1.32%
Ethereum (ETH) $ 3,134.94 1.09%
XRP (XRP) $ 2.12 5.77%
Bittensor (TAO) $ 261.93 6.89%
Polkadot (DOT) $ 2.16 1.64%
Cardano (ADA) $ 0.4014 3.89%
Chainlink (LINK) $ 13.47 2.55%
Hyperliquid (HYPE) $ 25.14 2.54%
Monero (XMR) $ 435.16 1.29%
Hedera (HBAR) $ 0.125574 5.77%
Toncoin (TON) $ 1.85 3.07%