CVE-2025-30066
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 69.79%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-506
- Published
- 2025-03-15
- Last modified
- 2026-02-26
Affected products
- tj-actions changed-files
Weakness type
Related vulnerabilities
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-77651 — The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project...
- CVE-2026-77650 — The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a...
- CVE-2026-77649 — The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a...
- CVE-2026-73532 — Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
- CVE-2026-73533 — Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
- CVE-2026-48161 — react18-use was vulnerable to malicious code execution via compromised commits
- CVE-2026-48160 — react-tracked was vulnerable to malicious code execution via compromised commits