GHSA-qmg3-hpqr-gqvc · Severity: high · Ecosystem: actions — Multiple Reviewdog actions were compromised during a specific time period
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.
Conclusion & alert: CVE-2025-30154 is rated Critical Active Threat (92.9/100): CVSS High severity, with high exploitation likelihood (EPSS 37.08%, 97th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-03-24) affecting reviewdog / action-setup GitHub Action. a weakness (CWE-506) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability · CISA KEV detail
: 2025-03-24
: 2025-04-14
: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-06 | 37.66% | 37.08% | -0.58% |
| 2 | 2026-06-05 | 34.56% | 37.66% | +3.10% |
| 3 | 2026-05-22 | — | 34.56% | — |
Full EPSS history (25 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.6 | 3.1 | HIGH |
|
3.9 | 4.0 | [email protected] |
| 8.6 | 3.1 | HIGH |
|
3.9 | 4.0 | [email protected] |
GHSA-qmg3-hpqr-gqvc · Severity: high · Ecosystem: actions — Multiple Reviewdog actions were compromised during a specific time period
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| reviewdog | action-ast-grep | < 1.26.2 | cpe:2.3:a:reviewdog:action-ast-grep:*:*:*:*:*:*:*:* |
| reviewdog | action-composite-template | < 0.20.2 | cpe:2.3:a:reviewdog:action-composite-template:*:*:*:*:*:*:*:* |
| reviewdog | action-setup | 1 | cpe:2.3:a:reviewdog:action-setup:1:*:*:*:*:*:*:* |
| reviewdog | action-shellcheck | < 1.29.2 | cpe:2.3:a:reviewdog:action-shellcheck:*:*:*:*:*:*:*:* |
| reviewdog | action-staticcheck | < 1.26.2 | cpe:2.3:a:reviewdog:action-staticcheck:*:*:*:*:*:*:*:* |
| reviewdog | action-typos | < 1.17.2 | cpe:2.3:a:reviewdog:action-typos:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/reviewdog/action-setup/commit/3f401fe1d58fe77e10d665ab713057375e39b887 | Patch |
| https://github.com/reviewdog/action-setup/commit/f0d342d24037bb11d26b9bd8496e0808ba32e9ec | Patch |
| https://github.com/reviewdog/reviewdog/issues/2079 | Issue Tracking Vendor Advisory |
| https://github.com/reviewdog/reviewdog/security/advisories/GHSA-qmg3-hpqr-gqvc | Vendor Advisory |
| https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup | Exploit Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30154 | US Government Resource |