AI Weekly Malaysia

Back to items Summaries

We got admin access to Baseten's production GitHub

ID
24984
Status
summarized
Published
16 Sep 2026, 2:11 AM
Fetched
17 Sep 2026, 11:47 PM
Provider
Hacker News
Category
dev-community
Original URL
https://www.strix.ai/blog/baseten-harbor-github-pat-takeover
Source URL
https://hnrss.org/best

Summary

Score
7.5
Created
18 Sep 2026, 12:53 AM
Tags
Audience
developersai_ml_learnerssaas_founders

What happened

Security company Strix ran their autonomous hacking agent against Baseten's infrastructure before adopting it for inference, and within ~25 minutes found a live GitHub personal access token embedded in a container image on a publicly accessible Harbor registry project. The token had admin and push access to Baseten's main product repo, GitOps cluster repo, Homebrew tap, and per-customer private repos. The image was built in March 2023 and the token still worked when found in July 2026; Baseten confirmed it as critical and rotated the token within a day.

Why it matters

If you ship container images, audit them for embedded secrets — especially in public registry projects. A token baked into an image from 2023 remained live for over three years. If you use or evaluate third-party inference providers like Baseten, this illustrates that even well-funded vendors ($13B valuation) can leak production credentials through basic misconfigurations. Run black-box recon on your own subdomains and registry projects before someone else does.

Discussion angle

How many of us have checked whether our own container images — pushed to public or misconfigured private registry projects — contain live tokens or credentials from build time? This is a cheap, high-impact audit to run this week.

Top