Security company Strix reported that its autonomous hacking agent, Strix, discovered active GitHub personal access tokens within Baseten's container images in July 2026. The scan, which took approximately 25 minutes, identified a GitHub token stored in the build history of a Docker image.
Strix AI Agent Discovers Exposed GitHub Admin Tokens in Baseten Container Images
The discovered token, associated with the account basetenbot, granted administrative and push access to several critical repositories, including Baseten's main product repository, their GitOps repository (flux-cd), and their Homebrew tap. The vulnerability stemmed from a 2023 build process where a token was passed as a build argument, which Docker recorded in the image's metadata and configuration history.
Baseten's security team responded to the disclosure by locking down the registry project and rotating the token by the following afternoon. Strix noted that while the image files themselves might have been cleaned, the credentials remained accessible through the image's build history.
Sources
- We got admin access to Baseten's production GitHub in 25 minutes (Hacker News Frontpage, 2026-09-15)
- Strix GitHub
1 more sourcesHide sources
- 「APIキーは.envに」はもはや通用しない AIエージェントの“内通者化”をどう防ぐ? (ITmedia AI+, 2026-09-16)