Tj Actions develops a small collection of GitHub Actions focused on file and branch manipulation workflows, including products such as changed_files, branch_names, and verify_changed_files that operate within continuous-integration pipelines. The observed vulnerability surface for this vendor remains narrow and without a clear recurring weakness class pattern. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tj Actions over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30066HIGH tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 beca | Mar 15, 2025 | 8.6 | 84 | YES | NO |
CVE-2023-51664CRITICAL tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed | Dec 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-49291CRITICAL tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `gith | Dec 5, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-52137HIGH The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execut | Dec 29, 2023 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tj Actions.
Media articles that mention a CVE ID that affects a product developed by Tj Actions — matched by CVE ID, not by vendor name.