Vulnerability record · CVE-2025-30066 · published 15 March 2025
CVE-2025-30066: tj-actions/changed-files GitHub Action leaks secrets via modified tags
TTj Actions · Changed Files
The tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e58ed8, which contained malicious updateFeatures code. That code caused secrets to be exposed by reading actions logs, so any workflow referencing the affected tags could leak credentials. The flaw is a supply-chain compromise of a widely used third-party action, not a coding bug in the action's intended logic.
Description
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with active exploitation, high EPSS, and a supply-chain vector that exposes secrets across many CI/CD pipelines.
What it is
The tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e58ed8, which contained malicious updateFeatures code. That code caused secrets to be exposed by reading actions logs, so any workflow referencing the affected tags could leak credentials. The flaw is a supply-chain compromise of a widely used third-party action, not a coding bug in the action's intended logic.
Impact
An attacker who can read the workflow's actions logs gains access to secrets present in the runner environment, such as tokens and credentials. This can lead to downstream compromise of repositories, cloud accounts and CI/CD pipelines.
Attack surface
Reached remotely over the network through GitHub Actions workflows that reference the affected tags; no authentication or user interaction is required by the attacker. The malicious code runs automatically when the workflow executes.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-03-18, and EPSS gives a 30-day probability of 0.69794 (99.3rd percentile). Multiple references are tagged Exploit, confirming active exploitation.
What to do
- Immediately stop using affected tj-actions/changed-files tags v1 through v45.0.7 and pin the action to a known-good commit SHA or a fixed version.
- Rotate all secrets, tokens and credentials that were accessible to workflows that ran the compromised action during 2025-03-14 and 2025-03-15.
- Audit workflow run logs and repository history for unauthorized access or changes made with exposed credentials.
- Apply the vendor and CISA mitigations, and follow BOD 22-01 guidance for cloud services or discontinue use if mitigations are unavailable.
- Adopt hardening controls for GitHub Actions, such as restricting third-party actions and using a hardened runner.
Detection
- Search workflow files and run logs for references to tj-actions/changed-files tags v1 through v45.0.7 or commit 0e58ed8.
- Review GitHub Actions logs from 2025-03-14 and 2025-03-15 for unexpected output or secret exposure.
- Monitor for anomalous use of CI/CD credentials and tokens that were present in affected workflow runs.
- Check repository and organization audit logs for unexpected changes or access following the compromise window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-30066 to the Known Exploited Vulnerabilities catalog on 18 March 2025 as "tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability". Required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 April 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-30066 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-30066), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.