Strix agent found admin-level GitHub token exposed on Baseten infrastructure
Security firm Strix ran an unauthenticated scan against Baseten's public infrastructure and within 25 minutes uncovered a live GitHub personal access token with admin rights to Baseten's core product repo, GitOps repo, and Homebrew tap. The token, tied to a container image built in March 2023, had gone unnoticed for over three years and still granted read/write access to private customer repositories when discovered in July 2026. Baseten's security team confirmed the issue as critical and rotated the token within a day of disclosure.