CVE-2026-55884
Tilt’s HUD HTTP server in versions 0.20.8‑0.37.3 exposed unprotected endpoints. An unauthenticated user could trigger developer actions, modify Tiltfile arguments, read the engine state and session token, and call API server resources. The issue is fixed in Tilt 0.37.4.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Tilt micro‑service development environments, versions 0.20.8 through 0.37.3, used by developers deploying to Kubernetes.
Real-world impact
An attacker on the same network could execute arbitrary developer‑defined actions, alter configuration, steal the session token, and use it to access the Tilt API server, effectively gaining full control over the development environment.
Why this severity
The CVSS score of 9.2 reflects the lack of authentication (attack vector network, no privileges required), the high confidentiality impact (full engine state and token), and the ability to modify system state and invoke privileged API calls.
What to do about it
- 01Upgrade Tilt to version 0.37.4 or later.
NVD-referenced vendor advisory
Timeline
- Jul 10, 2026 · 24d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 5d agoAdvisory updatedThe NVD record was last revised.
- Jul 29, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.