← Vulnerability feed

Vulnerability record · CVE-2025-30154 · published 19 March 2025

CVE-2025-30154: reviewdog/action-setup GitHub Action leaks secrets to workflow logs

Reviewdog · Action Ast Grep

reviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into GitHub Actions workflow logs. Any reviewdog action that uses reviewdog/action-setup@v1 is affected regardless of version or pinning method, including action-shellcheck, action-composite-template, action-staticcheck, action-ast-grep, and action-typos. Because CI secrets are commonly exposed in workflow logs, this is a supply-chain compromise with direct credential exposure.

8.6 CVSS 3.1 High CISA KEV since 24 Mar 2025 EPSS 2.4% · top 16.4% CWE-506 · CWE-506
8.6CVSS 3.1 base score
2.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
6References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCISA KEV listing confirms active exploitation, and the flaw directly exposes CI secrets with no authentication or user interaction required.

What it is

reviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into GitHub Actions workflow logs. Any reviewdog action that uses reviewdog/action-setup@v1 is affected regardless of version or pinning method, including action-shellcheck, action-composite-template, action-staticcheck, action-ast-grep, and action-typos. Because CI secrets are commonly exposed in workflow logs, this is a supply-chain compromise with direct credential exposure.

Impact

An attacker gains access to secrets exposed in GitHub Actions workflow logs, such as tokens, credentials, or other sensitive values available to the workflow. Those secrets can then be used to access downstream systems, repositories, or cloud resources.

Attack surface

The flaw is reached through the GitHub Actions workflow supply chain when a workflow uses reviewdog/action-setup@v1 or a dependent reviewdog action. No authentication or user interaction is required from the victim beyond the workflow running, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-03-24, and a third-party advisory is tagged as an exploit reference. EPSS gives a 30-day probability of 0.02395 (83rd percentile), indicating elevated but not top-tier likelihood.

What to do

  • Replace or remove reviewdog/action-setup@v1 and any dependent reviewdog actions (action-shellcheck, action-composite-template, action-staticcheck, action-ast-grep, action-typos) from workflows, or pin to the patched commits referenced in the advisory.
  • Rotate all secrets, tokens, and credentials that were available to workflows using the affected actions during the compromise window.
  • Audit GitHub Actions workflow logs from March 11, 2025, 18:42 to 20:31 UTC for exposed secret values and treat any exposed credential as compromised.
  • Apply the vendor mitigations and CISA BOD 22-01 guidance, or discontinue use of the affected actions if mitigations cannot be applied.
  • Restrict workflow token permissions and use short-lived, least-privilege credentials to limit the blast radius of future supply-chain compromises.

Detection

  • Search GitHub Actions workflow logs for secret-like strings or unexpected output from reviewdog/action-setup steps.
  • Review workflow run history for executions of reviewdog/action-setup@v1 or dependent reviewdog actions during the compromise window.
  • Monitor for use of credentials that were present in affected workflows after March 11, 2025, especially anomalous access from CI-related identities.
  • Check repository and organization audit logs for unexpected changes to workflow files or action references.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-30154 to the Known Exploited Vulnerabilities catalog on 24 March 2025 as "reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability". Required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 14 April 2025.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-30154 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-8398DAEMON Tools Lite installers trojanized via supply chain compromiseAttackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.ex…KEVEPSS 0.96%analysed9.3CVE-2026-48027Nx Console VS Code extension shipped with embedded malicious codeA malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for ro…KEVEPSS 1.3%analysed9.6CVE-2026-45321TanStack npm packages published with credential-stealing malware via CI/CD chainEighty-four malicious versions across 42 @tanstack/* npm packages were published on 2026-05-11 using the legitimate GitHub Actions OIDC trusted-publi…KEVEPSS 1.1%analysed9.4CVE-2026-33634Trivy and trivy-action supply chain compromise via malicious release and tagsA threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-acti…KEVEPSS 1.7%analysed7.5CVE-2025-54313eslint-config-prettier npm package ships malicious install scriptVersions 8.10.1, 9.1.1, 10.1.6 and 10.1.7 of eslint-config-prettier contain embedded malicious code: installing the package runs an install.js that l…KEVEPSS 4.5%analysed9.3CVE-2025-59374ASUS Live Update client supply chain compromise with embedded malicious codeCertain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modi…KEVEPSS 1.2%analysed8.6CVE-2025-30066tj-actions/changed-files GitHub Action leaks secrets via modified tagsThe tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e5…KEVEPSS 72%analysed8.7CVE-2024-4978JAVS Viewer installer ships backdoored binary with forged signatureThe Justice AV Solutions Viewer Setup 8.3.7.250-1 installer contains an embedded malicious binary signed with an unexpected Authenticode signature, m…KEVEPSS 27%analysed

Source: NIST National Vulnerability Database (record CVE-2025-30154), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.