We got admin access to Baseten's production GitHub
- ID
- 24984
- Status
- summarized
- Published
- 16 Sep 2026, 2:11 AM
- Fetched
- 17 Sep 2026, 11:47 PM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://www.strix.ai/blog/baseten-harbor-github-pat-takeover
- Source URL
- https://hnrss.org/best
Summary
- Score
- 7.5
- Created
- 18 Sep 2026, 12:53 AM
- Tags
- Audience
- developersai_ml_learnerssaas_founders
What happened
Security company Strix ran their autonomous hacking agent against Baseten's infrastructure before adopting it for inference, and within ~25 minutes found a live GitHub personal access token embedded in a container image on a publicly accessible Harbor registry project. The token had admin and push access to Baseten's main product repo, GitOps cluster repo, Homebrew tap, and per-customer private repos. The image was built in March 2023 and the token still worked when found in July 2026; Baseten confirmed it as critical and rotated the token within a day.
Why it matters
If you ship container images, audit them for embedded secrets — especially in public registry projects. A token baked into an image from 2023 remained live for over three years. If you use or evaluate third-party inference providers like Baseten, this illustrates that even well-funded vendors ($13B valuation) can leak production credentials through basic misconfigurations. Run black-box recon on your own subdomains and registry projects before someone else does.
Discussion angle
How many of us have checked whether our own container images — pushed to public or misconfigured private registry projects — contain live tokens or credentials from build time? This is a cheap, high-impact audit to run this week.