CVE-2025-30066 is a critical supply chain vulnerability affecting tj-actions changed-files, allowing remote attackers to discover secrets by reading action logs. This vulnerability, rated 8.6 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), stems from a threat actor modifying older tags (v1-v45.0.7) to point to malicious code. The potential impact is severe, with a FAUCET Risk Score of 100/100 and an EPSS score indicating high exploitability. This CVE is actively exploited (KEV), has garnered significant community discussion (18 mentions), and extensive media coverage, despite no public exploit code being available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 45.0.7CPE matchmatch criteria | cpe:2.3:a:tj-actions:changed-files:*:*:*:*:*:*:*:* | ||
>= 1, < 46CPE match | cpe:2.3:a:tj-actions:changed-files:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.