CVE-2025-30066 Information
Description
tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were not originally affected but were modified by a threat actor to point at commit 0e58ed8 which contains the malicious updateFeatures code.)
Reference
https://github.com/chains-project/maven-lockfile/pull/1111 https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193 https://github.com/rackerlabs/genestack/pull/903 https://github.com/tj-actions/changed-files/issues/2463 https://news.ycombinator.com/item?id=43367987 https://news.ycombinator.com/item?id=43368870 https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/ https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463 https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
Share on: