Sources
Wiz Research: Critical Auth Bypass in Base44 Vibe Coding Platform Exposed Every Enterprise App on the Platform
Wiz Research disclosed a critical authentication bypass in Base44 (recently acquired by Wix) where providing only a non-secret app_id to undocumented registration and email verification endpoints created a verified account — bypassing all authentication including SSO — and granted full access to private enterprise applications. Potentially thousands of company chatbots and PII-laden apps were exposed. Wix patched within 24 hours and confirmed no prior exploitation, but the vulnerability underscores that the auth layer of vibe coding platforms cannot be trusted without independent security review.
Source
↳ Follow the thread