The vulnerability report and the account of its remediation were published by Strix; there is no independent confirmation in the materials.
Strix reported finding a live GitHub personal access token with administrative access to internal Baseten repositories in a Baseten image that could be downloaded without a token or authorization. According to Strix, Baseten made the registry project private and rotated the token the next day.
Strix reported that the token was in the build history of an image dated March 2023 and still worked in July 2026. According to Strix, the token had administrator and push rights to Baseten’s main product repository, its GitOps repository, which defines the desired state of the clusters, and its Homebrew tap. Strix said it did not clone the customer repository, push anything, or change any configuration, and immediately sent a vulnerability disclosure email.
The vulnerability report and the account of its remediation were published by Strix; there is no independent confirmation in the materials.
Claim check:
- Strix reported finding a live GitHub personal access token with administrative access to internal Baseten repositories. (confirmed only by the carrying publication: evidence; «About 25 minutes later, it had a live GitHub token with repository-level admin rights on internal Baseten repos.»)
- According to Strix, Baseten made the registry project private and rotated the token the next day. (confirmed only by the carrying publication: evidence; «They confirmed the issue as critical, locked down the registry project, and rotated the token by the next afternoon.»)
- Strix reported that the token was in the build history of an image dated March 2023 and still worked in July 2026. (confirmed only by the carrying publication: evidence; «The image build dated to March 2023 , and the token still worked when we found it in July 2026.»)
- According to Strix, the token had administrator and push rights to Baseten’s main product repository, its GitOps repository, and its Homebrew tap. (confirmed only by the carrying publication: evidence; «That token had admin and push access to Baseten’s main product repo, the GitOps repo that drives their clusters, and their Homebrew tap»)
- Strix said it did not clone the customer repository, push anything, or change any configuration, and immediately sent a vulnerability disclosure email. (confirmed by the publication itself: evidence; «We didn't clone the customer repo, push anything, or change any configuration. We stopped there and wrote the disclosure email immediately.»)
- Strix reported that the baseten/baseten-app image could be downloaded without a token or authorization. (confirmed only by the carrying publication: evidence; «Without any token or auth, Strix could list repositories, obtain anonymous pull tokens, and download the actual image manifests and blobs. That included an image called baseten/baseten-app .»)
Primary sources:
score 82.8 out of 100 · kind: incident