Urgent.News

What's breaking now, across thousands of outlets.

Tech

We got admin access to Baseten's production GitHub in 25 minutes

A security company, known for scanning third-party services, tested a popular product named Baseten. To ensure Baseten's security, they used an autonomous hacking agent called Strix. Within 25 minutes, Strix gained admin access to Baseten's production GitHub repository. This access allowed Strix to read/write data to Baseten's repositories, including customer-specific ones.

Strix discovered the vulnerability through a Harbor registry, where it found a public image called baseten/baseten-app. Inside the image, Strix found a GitHub personal access token along with AWS keys and other secrets. The token, which was used for building the image, had significant permissions, including admin and push access to Baseten's code repository.

The token was still valid three years later, posing a severe threat. Strix confirmed the severity of the issue, and Baseten's security team acted quickly, locking down the registry and rotating the token. The incident highlights the importance of securing build tokens and scrutinizing third-party dependencies before integrating them into sensitive systems.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at strix.ai →

More in Tech

More from Tuesday 15 September →