Fetching from the wire…
Vibe Coding2026-03-22 · source-backed
Providing only a non-secret app_id to undocumented endpoints created a verified account bypassing all authentication including SSO — granting full access to private enterprise applications. Potentially thousands of company chatbots and PII-laden apps were exposed. Wix patched within 24 hours. The auth layer of vibe coding platforms cannot be trusted without independent security review. Source
Each link below shares sources, entities, or timing with this story.
Shared entity: PII / Shared topic / Earlier coverage
Both cover PII; overlapping topics (apps, base44, coding); earlier PII coverage from 2026-03-11.
Shared entity: SSO / Shared topic / Earlier coverage
Both cover SSO; overlapping topics (access, company, enterprise); earlier SSO coverage from 2026-02-24.
Shared entity: SSO / Shared topic / What happened next
Both cover SSO; overlapping topics (access, company); picks up the SSO thread on 2026-08-02.
Both cover SSO; overlapping topics (access, application); picks up the SSO thread on 2026-07-29.
Both cover SSO; overlapping topics (access, apps); picks up the SSO thread on 2026-07-01.
Shared entity: Wiz Research / Same source domain / What happened next
Both cover Wiz Research; reported by the same outlet (wiz.io); picks up the Wiz Research thread on 2026-06-26.
Both cover Wiz Research; reported by the same outlet (wiz.io); picks up the Wiz Research thread on 2026-04-29.
Both cover Wiz Research; reported by the same outlet (wiz.io); picks up the Wiz Research thread on 2026-03-25.