BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical Base44 Flaw Let Hackers Bypass Authentication Controls

Wix Quickly Patches Critical Base44 Flaw Allowing Unauthorized Access to Private Apps, Highlighting Ongoing AI Security Risks

  • Critical vulnerability in Base44 allowed unauthorized access to private apps with only a public app ID.
  • Wiz researchers found and reported the flaw, and Wix patched it within 24 hours.
  • The issue bypassed authentication and Single Sign-On, exposing users’ data.
  • No evidence exists that attackers exploited the bug before the fix.
  • Recent incidents highlight ongoing Cybersecurity risks in AI and large language model tools.

On July 29, 2025, researchers disclosed a serious security flaw in the AI-powered coding platform Base44, which is owned by Wix. The security firm Wiz identified and reported the vulnerability, which allowed people to gain access to private apps built by users without proper authorization.

- Advertisement -

The bug let attackers register and verify accounts on private apps using only the app’s public identifier, known as “app_id.” According to Wiz’s report, the flaw could be exploited via two registration endpoints that lacked proper security checks. “The vulnerability we discovered was remarkably simple to exploit — by providing only a non-secret app_id value to undocumented registration and email verification endpoints, an attacker could have created a verified account for private applications on their platform,” the researchers said. Wix responded by issuing a patch within 24 hours of notification on July 9, 2025.

The threat bypassed standard authentication such as Single Sign-On (SSO), putting all app data at risk. Wiz explained that since the app_id was visible in the app’s URL and files, anyone could use it to create and verify new accounts on private projects. “After confirming our email address, we could just login via the SSO within the application page, and successfully bypass the authentication,” said security researcher Gal Nagli. There is no evidence available that the flaw was actively exploited before it was fixed.

The incident exposes challenges as companies adopt AI-driven tools like “vibe coding.” These platforms allow users to create programs through natural language prompts, but new security issues may arise that traditional systems do not cover. Researchers have also warned of attacks on popular large language model (LLM) systems, such as prompt injection attacks, Gemini-ai-cli-hijack”>malicious code execution, phishing, and even leaking credentials.

Security teams are now exploring strategies like toxic flow analysis, which predicts potential attack scenarios in AI systems. Meanwhile, misconfigured servers in AI ecosystems, such as Model Control Protocol (MCP) servers, have been found exposed to the internet without authentication, risking data leaks and service abuse. According to Knostic, attackers could extract sensitive tokens and keys stored on these servers, gaining access to connected services.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Stellar invests in German crypto registrar Cashlink

The Stellar Development Foundation is making a strategic investment in German crypto registrar Cashlink.Cashlink,...

Used Tesla Model X Demand Jumps Amid End of Production

Production of the Tesla Model X is ending this quarter at the company's California...

Accenture Joins Hedera Council to Build Trusted AI Infrastructure

Accenture joins the Hedera Council, becoming a governing member with equal voting rights and...

WLFI Token Plummets 18% After Controversial Lock Vote

The token price for World Liberty Financial (WLFI) fell 18% following a controversial governance...

Spain leads euro stablecoin usage on Brighty in 2025-2026

Spain accounts for 36% of EURC transactions and 25% of volume on the Brighty...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading