Security
Loading…

CVE-2025-30066

UNKNOWNKnown Exploited
Description

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

Timeline
Published:March 18th, 2025 12:00 AM
Last modified:March 18th, 2025 12:00 AM
Added to KEV:March 18th, 2025
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

tj-actions

Products

changed-files GitHub Action
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute