CVE-2025-30154HIGH 8.6CISA KEVEPSS p80.2%

CVE-2025-30154reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

reviewdog / action-setup GitHub Action

Description

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

Scoring

CVSS 3.18.6 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS2.20% probability of exploitation · percentile 80.2% · 2026-06-19T12:03:05Z
Published2025-03-19
Last modified2025-10-24

CISA KEV entry

Added to KEV: 2025-03-24

Underlying weaknesses· 1

CWE-506

References

  1. https://github.com/reviewdog/action-setup/commit/3f401fe1d58fe77e10d665ab713057375e39b887
  2. https://github.com/reviewdog/action-setup/commit/f0d342d24037bb11d26b9bd8496e0808ba32e9ec
  3. https://github.com/reviewdog/reviewdog/issues/2079
  4. https://github.com/reviewdog/reviewdog/security/advisories/GHSA-qmg3-hpqr-gqvc
  5. https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup
  6. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30154

1

TypeTargetConfidenceTier
WeaknessEmbedded Malicious Codecwe-5060%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryreviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerabilitykev-cve-2025-301540%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
CVE
CVE-2025-31479
CVE
CVE-2025-15617
CVE
CVE-2025-54416
CVE
CVE-2026-44358
CVE
CVE-2026-21256
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.