Vulnerability record · CVE-2025-30154 · published 19 March 2025
CVE-2025-30154: reviewdog/action-setup GitHub Action leaks secrets to workflow logs
Reviewdog · Action Ast Grep
reviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into GitHub Actions workflow logs. Any reviewdog action that uses reviewdog/action-setup@v1 is affected regardless of version or pinning method, including action-shellcheck, action-composite-template, action-staticcheck, action-ast-grep, and action-typos. Because CI secrets are commonly exposed in workflow logs, this is a supply-chain compromise with direct credential exposure.
Description
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Automated analysis
critical priorityCISA KEV listing confirms active exploitation, and the flaw directly exposes CI secrets with no authentication or user interaction required.
What it is
reviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into GitHub Actions workflow logs. Any reviewdog action that uses reviewdog/action-setup@v1 is affected regardless of version or pinning method, including action-shellcheck, action-composite-template, action-staticcheck, action-ast-grep, and action-typos. Because CI secrets are commonly exposed in workflow logs, this is a supply-chain compromise with direct credential exposure.
Impact
An attacker gains access to secrets exposed in GitHub Actions workflow logs, such as tokens, credentials, or other sensitive values available to the workflow. Those secrets can then be used to access downstream systems, repositories, or cloud resources.
Attack surface
The flaw is reached through the GitHub Actions workflow supply chain when a workflow uses reviewdog/action-setup@v1 or a dependent reviewdog action. No authentication or user interaction is required from the victim beyond the workflow running, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-03-24, and a third-party advisory is tagged as an exploit reference. EPSS gives a 30-day probability of 0.02395 (83rd percentile), indicating elevated but not top-tier likelihood.
What to do
- Replace or remove reviewdog/action-setup@v1 and any dependent reviewdog actions (action-shellcheck, action-composite-template, action-staticcheck, action-ast-grep, action-typos) from workflows, or pin to the patched commits referenced in the advisory.
- Rotate all secrets, tokens, and credentials that were available to workflows using the affected actions during the compromise window.
- Audit GitHub Actions workflow logs from March 11, 2025, 18:42 to 20:31 UTC for exposed secret values and treat any exposed credential as compromised.
- Apply the vendor mitigations and CISA BOD 22-01 guidance, or discontinue use of the affected actions if mitigations cannot be applied.
- Restrict workflow token permissions and use short-lived, least-privilege credentials to limit the blast radius of future supply-chain compromises.
Detection
- Search GitHub Actions workflow logs for secret-like strings or unexpected output from reviewdog/action-setup steps.
- Review workflow run history for executions of reviewdog/action-setup@v1 or dependent reviewdog actions during the compromise window.
- Monitor for use of credentials that were present in affected workflows after March 11, 2025, especially anomalous access from CI-related identities.
- Check repository and organization audit logs for unexpected changes to workflow files or action references.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-30154 to the Known Exploited Vulnerabilities catalog on 24 March 2025 as "reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability". Required action: Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 14 April 2025.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/reviewdog/action-setup/commit/3f401fe1d58fe77e10d665ab713057375e39b887 | Patch |
| https://github.com/reviewdog/action-setup/commit/f0d342d24037bb11d26b9bd8496e0808ba32e9ec | Patch |
| https://github.com/reviewdog/reviewdog/issues/2079 | Issue TrackingVendor Advisory |
| https://github.com/reviewdog/reviewdog/security/advisories/GHSA-qmg3-hpqr-gqvc | Vendor Advisory |
| https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30154 | US Government Resource |
Track CVE-2025-30154 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-30154), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.