Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue is fixed in version 0.37.4.
CVSS
No CVSS.
References
Configurations
No configuration.
History
10 Jul 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 22:16
Updated : 2026-07-29 20:17
NVD link : CVE-2026-55884
Mitre link : CVE-2026-55884
CVE.ORG link : CVE-2026-55884
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
