March 18, 2025 · Applied Cybernetics Group
CVE-2025-30066 — tj-actions changed-files GitHub Action
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
- Added to KEV
2025-03-18- Federal due date
2025-04-08- Vendor
- tj-actions
- Product
- changed-files GitHub Action
- EPSS
- 99.7th percentile (score 0.918, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2025-30066
CISA short description
tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.
Required action
Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.