CVE-2025-30066
Description
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
Summary dbcve.org
The tj-actions/changed-files GitHub Action versions v1 through v45.0.7 were compromised between March 14-15, 2025 when a threat actor modified tags to point to a malicious commit (0e58ed8) containing code that exposed secrets through action logs, allowing remote attackers to discover sensitive credentials.
Mitigation
Immediately update to version 46 or later, audit GitHub Actions logs for unauthorized access during the compromise window, and rotate any secrets that may have been exposed through logs.