CVE Explorer
CVE-2026-55883
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the token is served by the unauthenticated /api/websocket_token endpoint and the upgrader accepts clients that omit an Origin header. When the HUD is network-exposed, an attacker who can reach the listener can open the HUD WebSocket and receive the full view stream, including session state, Tiltfile contents, resource statuses, an
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"tilt","vendor":"tilt-dev","versions":[{"status":"affected","version":">= 0.24.0, < 0.37.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dfd39cb01bda1926e6eeb5e7d1f906dcf499ea159e3adf5826e193e2ef0d51bb · sha256:7894c88b3e4d2341… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.3,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:dfd39cb01bda1926e6eeb5e7d1f906dcf499ea159e3adf5826e193e2ef0d51bb · sha256:7894c88b3e4d2341… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dfd39cb01bda1926e6eeb5e7d1f906dcf499ea159e3adf5826e193e2ef0d51bb · sha256:7894c88b3e4d2341… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a","tags":["x_refsource_MISC"],"url":"https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dfd39cb01bda1926e6eeb5e7d1f906dcf499ea159e3adf5826e193e2ef0d51bb · sha256:7894c88b3e4d2341… · /containers/cna/references/2
{"name":"https://github.com/tilt-dev/tilt/pull/6776","tags":["x_refsource_MISC"],"url":"https://github.com/tilt-dev/tilt/pull/6776"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dfd39cb01bda1926e6eeb5e7d1f906dcf499ea159e3adf5826e193e2ef0d51bb · sha256:7894c88b3e4d2341… · /containers/cna/references/1
{"name":"https://github.com/tilt-dev/tilt/releases/tag/v0.37.4","tags":["x_refsource_MISC"],"url":"https://github.com/tilt-dev/tilt/releases/tag/v0.37.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dfd39cb01bda1926e6eeb5e7d1f906dcf499ea159e3adf5826e193e2ef0d51bb · sha256:7894c88b3e4d2341… · /containers/cna/references/3
{"name":"https://github.com/tilt-dev/tilt/security/advisories/GHSA-6m68-r693-78qx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/tilt-dev/tilt/security/advisories/GHSA-6m68-r693-78qx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dfd39cb01bda1926e6eeb5e7d1f906dcf499ea159e3adf5826e193e2ef0d51bb · sha256:7894c88b3e4d2341… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.