Skip to content

We got admin access to Baseten's production GitHub

8.5 relevance
Score Breakdown
technical depth
8
novelty
9
actionability
8
community
10
strategic
8
personal
9

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Security breach writeup revealing GitHub PAT token admin access to production, highly actionable for security and platform engineers.

AI/ML strix.ai
We wanted to use Baseten for inference. We ended up with admin access to Baseten GitHub repos - Strix
Summary

Strix's autonomous hacking agent discovered a live GitHub personal access token with admin and push access to Baseten's production repositories, including their main product repo and GitOps infrastructure, by scanning a publicly accessible Harbor container registry. The token, dating from March 2023 and still active in July 2026, was found without any credentials by enumerating subdomains and pulling anonymous image layers. Baseten's security team rotated the token within a day of disclosure, but the incident demonstrates how exposed container registries can leak critical infrastructure credentials.

Author

Alex Schapiro