CVE-2025-30066HIGH 8.6CISA KEVEPSS p98.6%

CVE-2025-30066tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

tj-actions / changed-files GitHub Action

Description

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

Scoring

CVSS 3.18.6 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS44.68% probability of exploitation · percentile 98.6% · 2026-06-18T12:00:27Z
Published2025-03-15
Last modified2025-11-05

CISA KEV entry

Added to KEV: 2025-03-18

Underlying weaknesses· 1

CWE-506

References

  1. https://blog.gitguardian.com/compromised-tj-actions/
  2. https://github.com/chains-project/maven-lockfile/pull/1111
  3. https://github.com/espressif/arduino-esp32/issues/11127
  4. https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193
  5. https://github.com/modal-labs/modal-examples/issues/1100
  6. https://github.com/rackerlabs/genestack/pull/903
  7. https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73/README.md?plain=1#L20-L28
  8. https://github.com/tj-actions/changed-files/issues/2463

1

TypeTargetConfidenceTier
WeaknessEmbedded Malicious Codecwe-5060%live

(incoming)1

TypeTargetConfidenceTier
KEVEntrytj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerabilitykev-cve-2025-300660%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
CVE
CVE-2025-54416
CVE
CVE-2025-31479
CVE
CVE-2025-15617
CVE
CVE-2026-1699
CVE
CVE-2025-10894
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.