Advisories for Golang/Github.com/Tilt-Dev/Tilt package

2026

Tilt: Missing authentication on the network-exposed Tilt HUD server

The Tilt HUD HTTP server exposes state-changing and sensitive-read endpoints with no authentication. When the HUD is bound to a non-loopback address, a network attacker can trigger the developer's pre-defined Tiltfile resources, tamper with Tiltfile arguments, read full engine state including the session token, and reach the Tilt apiserver through a token-attaching proxy.