CVE-2025-30066
HIGH
8,6
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,9088
Percentile
1,0th
Updated
EPSS Score Trend (Last 90 Days)
506
Embedded Malicious Code
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
All platforms may be affected
Application
Changed-Files by Tj-Actions
Version Range Affected
To
45.0.7
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:tj-actions:changed-files:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025…
https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-thir…
https://blog.gitguardian.com/compromised-tj-actions/
https://github.com/chains-project/maven-lockfile/pull/1111
https://github.com/espressif/arduino-esp32/issues/11127
https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/co…
https://github.com/modal-labs/modal-examples/issues/1100
https://github.com/rackerlabs/genestack/pull/903
https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054…
https://github.com/tj-actions/changed-files/issues/2463
https://github.com/tj-actions/changed-files/issues/2464
https://github.com/tj-actions/changed-files/issues/2477
https://news.ycombinator.com/item?id=43367987
https://news.ycombinator.com/item?id=43368870
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-…
https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files-s…
https://web.archive.org/web/20250315060250/https://github.com/tj-actions/change…
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-fil…
https://www.stream.security/post/github-action-supply-chain-attack-exposes-secr…
https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack
https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-att…