AI Pentesting Agent Found Admin GitHub Token in Baseten's Public Docker Registry in 25 Minutes
Security firm Strix used its autonomous AI pentesting agent to scan inference provider Baseten's public-facing infrastructure without credentials or source code access. Within 25 minutes, the agent discovered a live GitHub personal access token embedded in the build history of a Docker image stored in a publicly accessible Harbor container registry. The token, belonging to a bot account called basetenbot, had been exposed since March 2023 and granted admin and push access to Baseten's main product repository, its GitOps repo managing production clusters, and its Homebrew tap. Strix reported the vulnerability on July 13, and Baseten's security team made the registry private, confirmed the issue as critical, and rotated the token by the following afternoon. The root cause was a common Dockerfile pattern where a GitHub token passed as a build argument gets expanded into plain text and persisted in the image's build history.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in