CVE-2025-30066

HIGH KEV

tj-actions <46 - Info Disclosure

Title source: llm

Description

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

Exploits (2)

nomisec SCANNER 1 stars
by Checkmarx · poc
https://github.com/Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool
nomisec WRITEUP
by OS-pedrogustavobilro · poc
https://github.com/OS-pedrogustavobilro/test-changed-files

References (21)

... and 1 more

Scores

CVSS v3 8.6
EPSS 0.9156
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CISA KEV 2025-03-18
VulnCheck KEV 2025-03-14
ENISA EUVD EUVD-2025-6565
CWE
CWE-506
Status published
Products (2)
GitHub Actions/tj-actions/changed-files 0 - 46.0.1GitHub Actions
tj-actions/changed-files < 45.0.7
Published Mar 15, 2025
KEV Added Mar 18, 2025
Tracked Since Feb 18, 2026