High severityNVD Advisory· Published Jul 10, 2026· Updated Jul 14, 2026
CVE-2026-55883
CVE-2026-55883
Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the token is served by the unauthenticated /api/websocket_token endpoint and the upgrader accepts clients that omit an Origin header. When the HUD is network-exposed, an attacker who can reach the listener can open the HUD WebSocket and receive the full view stream, including session state, Tiltfile contents, resource statuses, and continued updates. This issue is fixed in version 0.37.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/tilt-dev/tiltGo | >= 0.24.0, < 0.37.4 | 0.37.4 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-6m68-r693-78qxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55883ghsaADVISORY
- github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0anvdWEB
- github.com/tilt-dev/tilt/pull/6776nvdWEB
- github.com/tilt-dev/tilt/releases/tag/v0.37.4nvdWEB
- github.com/tilt-dev/tilt/security/advisories/GHSA-6m68-r693-78qxnvdWEB
News mentions
0No linked articles in our index yet.