We got admin access to Baseten's production GitHub in 25 minutes
The team behind Strix — an autonomous hacking agent that needs cheap, fast inference — was evaluating Baseten as a vendor, noting it is a strong product, is valued at $13 billion, and is depended on by many serious companies. But as a security company, they scan third parties before handing over data, models, or code, preferring to find and fix problems before they start depending on a service. They say they do this with almost all of their vendors and have a high rate of finding serious issues.
They pointed Strix at *.baseten.co and let it run with no credentials or source code. Strix began with recon: enumerating hosts, checking certificate logs, and mapping the full attack surface — the post stresses that the most severe vulnerability is often on a forgotten subdomain, which is why black-box testing is recommended alongside testing with code access. It eventually found a Harbor container registry at gcp-us-east4-zlw.registry.baseten.co. Harbor groups images into projects, and one of those projects was public: with no token or authentication, Strix could list repositories, obtain anonymous pull tokens, and download actual image manifests and blobs, including an image named baseten/baseten-app. Rather than stopping at "exposed registry" — which could be intentional and would be a false positive — Strix pulled an image to determine the real impact.
About 25 minutes in, Strix came back with an active GitHub personal access token for basetenbot. That token had admin and push access to Baseten's main product repo, the GitOps repo that drives their clusters, and their Homebrew tap, plus read/write access to other private repositories including specific per-customer repos. The image build dated to March 2023, and the token still worked when it was found in July 2026.
The post credits Baseten's security team: they confirmed the issue as critical, locked down the registry project, and rotated the token by the next afternoon, handling it professionally and very quickly — which the authors say is often not the case. The writeup also quotes Strix's own reasoning trace, which judged that if the Harbor projects were not meant to be public, this was a real exposure rather than metadata noise, and that the chain matters: enumerate public projects, read artifact metadata, mint an anonymous service token, and continue from there.