Operator note

One URL ID exposed Wix enterprise apps - 24h patch closed gap

Wiz revealed a public app_id flaw letting anyone create SSO accounts on Wix Vibe tools. Learn how the one-step attack worked and how Wix fixed it in 24h.

Minimalist tech illustration of an exposed URL parameter unlocking multiple Wix enterprise logins with a swift 24-hour patch

Cloud security firm Wiz has disclosed a flaw in Wix Base44 Vibe that let attackers register rogue accounts and gain access to private enterprise applications. Wix deployed a patch within 24 hours, and no real-world exploitation has been confirmed.

Wix Vibe vulnerability

Researchers discovered that every Vibe app exposes its unique app_id in public URLs and in the manifest.json file. By copying that identifier, an attacker could initiate a registration request through the platform’s API even when sign-ups were disabled. Once the one-time password arrived by email, the new account could complete the single sign-on (SSO) flow and log in with full user privileges.

Key details and context

  • The app_id appears in paths such as /manifests/{app_id}/manifest.json, making it easy to harvest.
  • An attacker could send a POST request to /api/v1/auth/signup with the stolen value and any email address.
  • The system then emailed a one-time password that verified the account without rate limits.
  • Logging in through SSO granted the same permissions as trusted staff accounts.
  • Wix fixed the issue in less than a day after Wiz notified the company.
  • Wiz has found no evidence of active exploitation.

Base44, launched by Wix in 2023, enables employees to build internal tools with minimal code. Wiz notes that fast low-code development can introduce security gaps when sensitive identifiers are left in public files.

Source citations

Wiz Research Uncovers Critical Vulnerability in AI Vibe Coding platform Base44 Allowing Unauthorized Access to Private Applications
Wix statement (via Wix.com)

Keep reading

Related articles

AI powered shopping cart protocol illustration with funnel price tag alert loyalty user tapping toggleInside Google's Universal Commerce Protocol that lets AI agents tap carts, catalogs and loyalty pricing2 min readMinimalist illustration of AI checkout hub with Cart Catalog Identity cards and user tapping settingsGoogle quietly upgrades AI shopping protocol: what Cart, Catalog and Identity Linking change next2 min readMinimalist tablet health UI privacy risk toggle character adjusting shield and prescription funnelGoogle and DocMorris Launch AI Health Companion for Europe - What Changes Next2 min readMinimalist site health dashboard illustration with 404 410 toggle funnel filtering errors into green checksWorried About Endless 404 Reports In Search Console? John Mueller Reveals What They Really Mean3 min read