Researchers Gained Admin Access to Baseten's Production GitHub in 25 Minutes via PAT Takeover

bearsyankees · hn · 2026-09-16

Security firm Strix published a writeup showing how they took over Baseten's production GitHub in just 25 minutes by abusing an over-scoped GitHub Personal Access Token (PAT).

The post walks through the full attack chain: how over-privileged PATs leak, how the token enabled lateral movement into production, and why long-lived credentials in CI/CD pipelines remain a systemic risk for AI infrastructure companies.

A useful cautionary case for any team wiring GitHub tokens into deployment pipelines.

Original post →

More from Infra

Infra channel →