CVE-2026-55884
Critical · CVSS 9.2github.com/tilt-dev/tilt — Missing Authentication for Critical Function (unauthenticated HTTP handler access)
- CVSS
- 9.2
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-306
Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue is fixed in version 0.37.4.
Search profile — drives PoC discovery
Symbols gorilla/muxHUDhttp server/proxysession tokenTiltfileapiservertoken-attachinghud handlerengine state
Keywords CVE-2026-55884GHSA-c73q-8xxr-rgqmtilt-dev tilt unauthenticatedtilt HUD HTTP no authtilt proxy handler exploittilt gorilla mux no middlewaretilt session token leaktilt 0.37.3 unauthenticatedCWE-306 tilt
Versions: 0.20.8 through 0.37.3
Affected packages
| Go | github.com/tilt-dev/tilt | 0.20.8 → 0.37.4 |
References
Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z