CVE-2026-55884: Tilt-Dev Tilt

Critical severity, CVSS 9.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue is fixed in version 0.37.4.

Affected products

  • Tilt-Dev Tilt: from 0.20.8, before 0.37.4 (fixed in 0.37.4)

Published 2026-07-10. Last modified 2026-07-29.