A critical vulnerability in the AI vibe coding platform Base44 allowed unauthorized access to private applications by exploiting unauthenticated registration and email verification endpoints. Attackers could use a publicly available `app_id` to create verified accounts, bypassing authentication controls including SSO and granting full access to sensitive enterprise data.
Why This Matters
Publisher reporting describes a security event affecting Base44. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether Base44 is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.
Affected
AI Vibe CodingBase44Critical Vulnerability