← Back to CVE List
Vulnerability Intelligence Report
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

CVE-2025-30066

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
8.6
HIGH
Exploitability:3.9
Impact Score:4.0
EPSS Probability:41.01%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-506 ↗CWE-506 Embedded Malicious Code

Affected Products & Versions

Vendor Product Affected Versions
tj-actions changed-files 1 < 46 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
41.008%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2025-03-15T00:00:00
Published2025-03-15T00:00:00
Last Updated2026-02-26T19:09:29

LINK COPIED TO CLIPBOARD