Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Flaw in Vibe Coding Platform Base44 Exposed Private Enterprise Applications

Flaw in Vibe Coding Platform Base44 Exposed Private Enterprise Applications

Posted on July 30, 2025July 30, 2025 By CWS

Researchers at cloud safety big Wiz have found a vital vulnerability within the vibe coding platform Base44 that would have been exploited to achieve entry to personal purposes and delicate information belonging to enterprises that use it.

Base44, just lately acquired by website-building big Wix, is a vibe coding platform reportedly utilized by 1000’s of enterprises. Vibe coding permits customers to generate code based mostly on pure language prompts fed to AI instruments. 

Wiz researchers just lately analyzed Base44’s publicly accessible belongings and found some API endpoints that might be abused to bypass authentication. 

They discovered that endpoints designed for registering a brand new consumer with an e mail tackle and password and verifying the consumer with a one-time password didn’t require authentication, enabling anybody to register for personal purposes so long as they’d the goal’s ‘app_id’ worth.

Be taught Extra About Securing AI at SecurityWeek’s AI Threat Summit – August 19-20, 2025 on the Ritz-Carlton, Half Moon Bay

The researchers rapidly found that the required ‘app_id’ was hardcoded in every utility’s URI and manifest.json file path. This enabled them to register new consumer accounts for purposes they didn’t personal. 

“Throughout our analysis we managed to verify authentication bypass was accessible throughout a number of enterprise purposes that utilized the favored vibe coding platform for inner chatbots, data bases, PII & HR operations – vital delicate information that would have been leaked to unauthorized attackers,” Wiz defined. 

The corporate added, “What made this vulnerability significantly regarding was its simplicity – requiring solely fundamental API data to use. This low barrier to entry meant that attackers may systematically compromise a number of purposes throughout the platform with minimal technical sophistication.”Commercial. Scroll to proceed studying.

Wix patched the vulnerability inside 24 hours of being notified and its investigation confirmed that it had not been exploited within the wild previous to the repair being rolled out. Because the patch was utilized on the server facet, clients don’t must take any motion.

Associated: Ought to We Belief AI? Three Approaches to AI Fallibility

Associated: Google Says AI Agent Thwarted Exploitation of Essential Vulnerability

Associated: Google Gemini Tricked Into Displaying Phishing Message Hidden in E mail

Security Week News Tags:Applications, Base44, Coding, Enterprise, Exposed, Flaw, Platform, Private, Vibe

Post navigation

Previous Post: Minnesota Activates National Guard in Response to Cyberattack
Next Post: Cost of Data Breach in US Rises to $10.22 Million, Says Latest IBM Report

Related Posts

Bonfy.AI Raises .5 Million for Adaptive Content Security Platform Bonfy.AI Raises $9.5 Million for Adaptive Content Security Platform Security Week News
Interpol Targets Infostealers: 20,000 IPs Taken Down, 32 Arrested, 216,000 Victims Notified Interpol Targets Infostealers: 20,000 IPs Taken Down, 32 Arrested, 216,000 Victims Notified Security Week News
Cyberattack on Beer Giant Asahi Disrupts Production  Cyberattack on Beer Giant Asahi Disrupts Production  Security Week News
New Research Links VPN Apps, Highlights Security Deficiencies New Research Links VPN Apps, Highlights Security Deficiencies Security Week News
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider Security Week News
Cyera Raises 0 Million at  Billion Valuation Cyera Raises $400 Million at $9 Billion Valuation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News