CVE-2025-30066

Exp

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

Published: 2025-03-15 Last update: 2025-11-05 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2025-30066 is rated Critical Active Threat (95/100): CVSS High severity, with high exploitation likelihood (EPSS 44.68%, 99th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-03-18) affecting tj-actions / changed-files GitHub Action. a weakness (CWE-506) Unauthenticated remote administrative access may be possible. EPSS rose +1.05% over the last day, indicating growing attacker interest. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

CISA KEV Record for CVE-2025-30066

Name: tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability · CISA KEV detail

Exploit added: 2025-03-18

Action due: 2025-04-08

Required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Public exploit references (Exploit-DB) for CVE-2025-30066

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2025-30066

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-16 43.63% 44.68% +1.05%
2 2026-06-15 91.54% 43.63% -47.91%
3 2026-06-09 91.54%

Full EPSS history (66 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2025-30066

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.6 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
3.9 4.0 [email protected]
8.6 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:N)
Service keeps running; no real outage angle.
3.9 4.0 [email protected]

Weakness enumeration for CVE-2025-30066

GitHub Security Advisory for CVE-2025-30066

GHSA-mrrh-fwg8-r2c3 · Severity: high · Ecosystem: actions — tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.

Affected software / configurations for CVE-2025-30066

Vendor Product Version Raw CPE
tj-actions changed-files <= 45.0.7 cpe:2.3:a:tj-actions:changed-files:*:*:*:*:*:*:*:*

References for CVE-2025-30066

URL Tags
https://blog.gitguardian.com/compromised-tj-actions/ Exploit Third Party Advisory
https://github.com/chains-project/maven-lockfile/pull/1111 Issue Tracking
https://github.com/espressif/arduino-esp32/issues/11127 Issue Tracking
https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193 Product
https://github.com/modal-labs/modal-examples/issues/1100 Issue Tracking
https://github.com/rackerlabs/genestack/pull/903 Issue Tracking
https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73/README.md?plain=1#L20-L28 Product
https://github.com/tj-actions/changed-files/issues/2463 Issue Tracking
https://github.com/tj-actions/changed-files/issues/2464 Issue Tracking
https://github.com/tj-actions/changed-files/issues/2477 Issue Tracking
https://news.ycombinator.com/item?id=43367987 Issue Tracking Third Party Advisory
https://news.ycombinator.com/item?id=43368870 Issue Tracking Third Party Advisory
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/ Third Party Advisory
https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files-supply-chain-attack-cve-2025-30066/ Mitigation Third Party Advisory
https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463 Issue Tracking
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised Exploit Mitigation Third Party Advisory
https://www.stream.security/post/github-action-supply-chain-attack-exposes-secrets-what-you-need-to-know-and-how-to-respond Third Party Advisory
https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack Third Party Advisory
https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066 Third Party Advisory
https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-github-action-cve-2025-30066 Third Party Advisory US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30066 US Government Resource
cvelogic Threat Intelligence