HIGH

CVE-2025-30066

Tj-actions Changed Files 2025-03-15 CVSS v3.1
CVSS
8.6
KEV

Description

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

Summary dbcve.org

The tj-actions/changed-files GitHub Action versions v1 through v45.0.7 were compromised between March 14-15, 2025 when a threat actor modified tags to point to a malicious commit (0e58ed8) containing code that exposed secrets through action logs, allowing remote attackers to discover sensitive credentials.

Mitigation

Immediately update to version 46 or later, audit GitHub Actions logs for unauthorized access during the compromise window, and rotate any secrets that may have been exposed through logs.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-506

EPSS Score

69.79%
Probability of exploitation in next 30 days
99.3th percentile

References

https://blog.gitguardian.com/compromised-tj-actions/ Exploit, Third Party Advisory https://github.com/chains-project/maven-lockfile/pull/1111 Issue Tracking https://github.com/espressif/arduino-esp32/issues/11127 Issue Tracking https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193 Product https://github.com/modal-labs/modal-examples/issues/1100 Issue Tracking https://github.com/rackerlabs/genestack/pull/903 Issue Tracking https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73/README.md?plain=1#L20-L28 Product https://github.com/tj-actions/changed-files/issues/2463 Issue Tracking https://github.com/tj-actions/changed-files/issues/2464 Issue Tracking https://github.com/tj-actions/changed-files/issues/2477 Issue Tracking https://news.ycombinator.com/item?id=43367987 Issue Tracking, Third Party Advisory https://news.ycombinator.com/item?id=43368870 Issue Tracking, Third Party Advisory https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/ Third Party Advisory https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files-supply-chain-attack-cve-2025-30066/ Mitigation, Third Party Advisory https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463 Issue Tracking https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised Exploit, Mitigation, Third Party Advisory https://www.stream.security/post/github-action-supply-chain-attack-exposes-secrets-what-you-need-to-know-and-how-to-respond Third Party Advisory https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack Third Party Advisory https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066 Third Party Advisory https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-github-action-cve-2025-30066 Third Party Advisory, US Government Resource https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30066 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE