{"id":"GHSA-6m68-r693-78qx","summary":"Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream","details":"## Summary\nThe Tilt HUD WebSocket (`/ws/view`) is gated by a CSRF token, but the token is served by an unauthenticated endpoint and the upgrader accepts any client that omits an `Origin` header. When the HUD is network-exposed, an attacker can open the HUD stream and read the developer's session state.\n\n## Details\nThe upgrader accepts a connection when the `csrf` query parameter matches a process-wide token (`websocketCSRFToken`). That token is served as `text/plain` by an unauthenticated handler (`WebsocketToken`, mounted at `/api/websocket_token`), so any reachable caller can fetch it and connect to `/ws/view?csrf=\u003ctoken\u003e`. When the parameter does not match, the upgrader falls back to a same-origin check that returns true when the `Origin` header is absent, so a non-browser client that omits `Origin` is accepted anyway. The token has no per-session binding.\n\n## Impact\nAn attacker who can reach the HUD listener can open the HUD WebSocket and receive the full view stream — session state, Tiltfile contents, resource statuses, and continued updates — defeating the intended anti-CSWSH protection.\n\n### Conditions for exploitation\n- Affected version in `\u003e= 0.24.0, \u003c= 0.37.3`.\n- HUD bound to a non-loopback address (`tilt up --host 0.0.0.0`, or `TILT_HOST` set).\n- Network reachability to the listener (default port `10350`).\n\n### Not affected\n- The default loopback-only bind is not reachable from the network.\n\n## Workarounds\nUse the default loopback bind (omit `--host`, unset `TILT_HOST`). No complete workaround short of upgrading for non-loopback deployments.","aliases":["CVE-2026-55883","GO-2026-5181"],"modified":"2026-07-21T14:00:28.240579354Z","published":"2026-06-19T13:53:35Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-19T13:53:35Z","nvd_published_at":"2026-07-10T22:16:44Z","cwe_ids":["CWE-345"]},"references":[{"type":"WEB","url":"https://github.com/tilt-dev/tilt/security/advisories/GHSA-6m68-r693-78qx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55883"},{"type":"WEB","url":"https://github.com/tilt-dev/tilt/pull/6776"},{"type":"WEB","url":"https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a"},{"type":"PACKAGE","url":"https://github.com/tilt-dev/tilt"},{"type":"WEB","url":"https://github.com/tilt-dev/tilt/releases/tag/v0.37.4"}],"affected":[{"package":{"name":"github.com/tilt-dev/tilt","ecosystem":"Go","purl":"pkg:golang/github.com/tilt-dev/tilt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.24.0"},{"fixed":"0.37.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-6m68-r693-78qx/GHSA-6m68-r693-78qx.json","last_known_affected_version_range":"\u003c= 0.37.3"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}