CVE-2025-30154 describes a supply chain compromise within reviewdog/action-setup@v1, a GitHub Action, and other dependent reviewdog actions, where malicious code was injected to exfiltrate exposed secrets from GitHub Actions Workflow Logs. This vulnerability carries a high CVSS score of 8.6, indicating a critical risk due to its network-based attack vector, low complexity, and high confidentiality impact. The CVE is actively exploited, as confirmed by its presence in the KEV catalog, and has garnered significant community discussion and media coverage, despite the absence of public exploit tools like Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.26.2CPE matchmatch criteria | cpe:2.3:a:reviewdog:action-ast-grep:*:*:*:*:*:*:*:* | ||
< 0.20.2CPE matchmatch criteria | cpe:2.3:a:reviewdog:action-composite-template:*:*:*:*:*:*:*:* | ||
1CPE matchmatch criteria | cpe:2.3:a:reviewdog:action-setup:1:*:*:*:*:*:*:* | ||
< 1.29.2CPE matchmatch criteria | cpe:2.3:a:reviewdog:action-shellcheck:*:*:*:*:*:*:*:* | ||
< 1.26.2CPE matchmatch criteria | cpe:2.3:a:reviewdog:action-staticcheck:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.