Vulnerability Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue is fixed in version 0.37.4.
Related Weaknesses (CWE)
References
- https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a
- https://github.com/tilt-dev/tilt/pull/6776
- https://github.com/tilt-dev/tilt/releases/tag/v0.37.4
- https://github.com/tilt-dev/tilt/security/advisories/GHSA-c73q-8xxr-rgqm
FAQ
What is CVE-2026-55884?
CVE-2026-55884 is a documented vulnerability. Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middle...
How severe is CVE-2026-55884?
CVSS scoring is not yet available for CVE-2026-55884. Check NVD for updates.
Is there a patch for CVE-2026-55884?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.