CVE-2025-30066

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected...

Basic Information

CVE State
PUBLISHED
Reserved Date
March 15, 2025
Published Date
March 15, 2025
Last Updated
March 22, 2025
Vendor
tj-actions
Product
changed-files
Description
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

CVSS Scores

CVSS v3.1

8.6 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2025-03-18 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2025-03-18 14:33:29 UTC) Source

References

https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193 https://github.com/tj-actions/changed-files/issues/2463 https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/ https://news.ycombinator.com/item?id=43368870 https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463 https://news.ycombinator.com/item?id=43367987 https://github.com/rackerlabs/genestack/pull/903 https://github.com/chains-project/maven-lockfile/pull/1111 https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files-supply-chain-attack-cve-2025-30066/ https://github.com/espressif/arduino-esp32/issues/11127 https://github.com/modal-labs/modal-examples/issues/1100 https://github.com/tj-actions/changed-files/issues/2464 https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73/README.md?plain=1#L20-L28 https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066 https://www.stream.security/post/github-action-supply-chain-attack-exposes-secrets-what-you-need-to-know-and-how-to-respond https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack https://github.com/tj-actions/changed-files/issues/2477 https://blog.gitguardian.com/compromised-tj-actions/

Known Exploited Vulnerability Information

Source Added Date
CISA 2025-03-18 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool

Type: github • Created: 2025-03-18 14:33:29 UTC • Stars: 1