HeadlinesBriefing favicon HeadlinesBriefing.com

Baseten Exposed GitHub Admin Token via Public Harbor Registry

Hacker News •
×

We were about to trust Baseten with our data, so we ran Strix to ensure security. About 25 minutes later, it had a live GitHub token with repository-level admin rights on internal Baseten repos.

We build Strix, an autonomous hacking agent, needing cheap and fast inference. Baseten is a great product, valued at $13 billion, with many serious companies depending on them. But as a security company, we scan vendors before sharing data. We pointed Strix at *.baseten.co without credentials. It found an active GitHub personal access token for basetenbot, with admin and push access to Baseten's main product repo, Git Ops repo, Homebrew tap, and read/write access to other private repositories. The image build dated to March 2023, and the token still worked in July 2026.

Kudos to Baseten's security team: they confirmed the issue as critical, locked down the registry project, and rotated the token by the next afternoon.

Strix enumerated hosts and found a Harbor registry at gcp-us-east4-zlw.registry.baseten.co. A public project allowed anonymous pull of images, including baseten/baseten-app. Strix pulled layers, ran TruffleHog, and found the token in the image config.