RaqibCTI
CVE

CVE-2025-30066

P2
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
tj-actions · changed-files GitHub Action
Date added (CISA)
2025-03-18
Remediation due
2025-04-08
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

Source: NVD ↗ · CISA KEV Catalog ↗