← Vulnerability feed

Vulnerability record · CVE-2025-30066 · published 15 March 2025

CVE-2025-30066: tj-actions/changed-files GitHub Action leaks secrets via modified tags

TTj Actions · Changed Files

The tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e58ed8, which contained malicious updateFeatures code. That code caused secrets to be exposed by reading actions logs, so any workflow referencing the affected tags could leak credentials. The flaw is a supply-chain compromise of a widely used third-party action, not a coding bug in the action's intended logic.

8.6 CVSS 3.1 High CISA KEV since 18 Mar 2025 EPSS 72% · top 0.6% CWE-506 · CWE-506
8.6CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
21References, 2 tagged exploit
24 Sep 2026Last modified by NVD

Description

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with active exploitation, high EPSS, and a supply-chain vector that exposes secrets across many CI/CD pipelines.

What it is

The tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e58ed8, which contained malicious updateFeatures code. That code caused secrets to be exposed by reading actions logs, so any workflow referencing the affected tags could leak credentials. The flaw is a supply-chain compromise of a widely used third-party action, not a coding bug in the action's intended logic.

Impact

An attacker who can read the workflow's actions logs gains access to secrets present in the runner environment, such as tokens and credentials. This can lead to downstream compromise of repositories, cloud accounts and CI/CD pipelines.

Attack surface

Reached remotely over the network through GitHub Actions workflows that reference the affected tags; no authentication or user interaction is required by the attacker. The malicious code runs automatically when the workflow executes.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-03-18, and EPSS gives a 30-day probability of 0.69794 (99.3rd percentile). Multiple references are tagged Exploit, confirming active exploitation.

What to do

  • Immediately stop using affected tj-actions/changed-files tags v1 through v45.0.7 and pin the action to a known-good commit SHA or a fixed version.
  • Rotate all secrets, tokens and credentials that were accessible to workflows that ran the compromised action during 2025-03-14 and 2025-03-15.
  • Audit workflow run logs and repository history for unauthorized access or changes made with exposed credentials.
  • Apply the vendor and CISA mitigations, and follow BOD 22-01 guidance for cloud services or discontinue use if mitigations are unavailable.
  • Adopt hardening controls for GitHub Actions, such as restricting third-party actions and using a hardened runner.

Detection

  • Search workflow files and run logs for references to tj-actions/changed-files tags v1 through v45.0.7 or commit 0e58ed8.
  • Review GitHub Actions logs from 2025-03-14 and 2025-03-15 for unexpected output or secret exposure.
  • Monitor for anomalous use of CI/CD credentials and tokens that were present in affected workflow runs.
  • Check repository and organization audit logs for unexpected changes or access following the compromise window.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-30066 to the Known Exploited Vulnerabilities catalog on 18 March 2025 as "tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability". Required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 8 April 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://blog.gitguardian.com/compromised-tj-actions/ ExploitThird Party Advisory
https://github.com/chains-project/maven-lockfile/pull/1111 Issue Tracking
https://github.com/espressif/arduino-esp32/issues/11127 Issue Tracking
https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions Product
https://github.com/modal-labs/modal-examples/issues/1100 Issue Tracking
https://github.com/rackerlabs/genestack/pull/903 Issue Tracking
https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73/README.md?plain=1#L20-L28 Product
https://github.com/tj-actions/changed-files/issues/2463 Issue Tracking
https://github.com/tj-actions/changed-files/issues/2464 Issue Tracking
https://github.com/tj-actions/changed-files/issues/2477 Issue Tracking
https://news.ycombinator.com/item?id=43367987 Issue TrackingThird Party Advisory
https://news.ycombinator.com/item?id=43368870 Issue TrackingThird Party Advisory
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/ Third Party Advisory
https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files-supply-chain-attack-cve-2025-30066/ MitigationThird Party Advisory
https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463 Issue Tracking
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised ExploitMitigationThird Party Advisory
https://www.stream.security/post/github-action-supply-chain-attack-exposes-secrets-what-you-need-to-know-and-how-to-resp Third Party Advisory
https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack Third Party Advisory
https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066 Third Party Advisory
https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-github-action-cve-2025-30066 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30066 US Government Resource

Track CVE-2025-30066 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-51664Tj-actions changed-files injection vulnerabilitytj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows fo…EPSS 3.4%9.3CVE-2026-8398DAEMON Tools Lite installers trojanized via supply chain compromiseAttackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.ex…KEVEPSS 0.96%analysed9.3CVE-2026-48027Nx Console VS Code extension shipped with embedded malicious codeA malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for ro…KEVEPSS 1.3%analysed9.6CVE-2026-45321TanStack npm packages published with credential-stealing malware via CI/CD chainEighty-four malicious versions across 42 @tanstack/* npm packages were published on 2026-05-11 using the legitimate GitHub Actions OIDC trusted-publi…KEVEPSS 1.1%analysed9.4CVE-2026-33634Trivy and trivy-action supply chain compromise via malicious release and tagsA threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-acti…KEVEPSS 1.7%analysed7.5CVE-2025-54313eslint-config-prettier npm package ships malicious install scriptVersions 8.10.1, 9.1.1, 10.1.6 and 10.1.7 of eslint-config-prettier contain embedded malicious code: installing the package runs an install.js that l…KEVEPSS 4.5%analysed9.3CVE-2025-59374ASUS Live Update client supply chain compromise with embedded malicious codeCertain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modi…KEVEPSS 1.2%analysed8.6CVE-2025-30154reviewdog/action-setup GitHub Action leaks secrets to workflow logsreviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into G…KEVEPSS 2.4%analysed

Source: NIST National Vulnerability Database (record CVE-2025-30066), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.