Cloud security company Wiz discovered a critical flaw in Wix’s Base44 vibe coding platform that enabled attackers to bypass authentication and gain access to private enterprise applications. The relative simplicity of finding what should have been a secret app ID number, and using it to gain access, made the vulnerability a serious concern.
Exposed Sensitive Identification Number
An apparently randomly generated identification number, called an app_id, was embedded in public-facing paths such as the application URL and the manifest.json file….








