A supply-chain compromise of the third-party GitHub Action tj-actions/changed-files, tracked as CVE-2025-30066, potentially exposed workflow secrets in repositories using the action. The action was used by more than 23,000 repositories, but that figure does not establish how many experienced secret exposure. Investigators identified a possible link to the compromise of reviewdog/action-setup@v1, tracked as CVE-2025-30154, and reported that multiple Reviewdog actions were affected during a specific timeframe.
CISA issued an alert naming both compromised actions and added both vulnerabilities to its Known Exploited Vulnerabilities Catalog. Organizations should identify affected action usage, review workflow logs for secret exposure, update compromised workflow references, rotate potentially exposed secrets, and investigate suspicious activity. The potential impact extends beyond workflow execution: exposed credentials could enable unauthorized access to connected systems and services.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2025-30066 and CVE-2025-30154 to its Known Exploited Vulnerabilities Catalog.
Investigators identified a possible connection between the tj-actions/changed-files compromise and the breach of reviewdog/action-setup@v1. The relationship remained tentative, and the investigation was ongoing when FortiGuard published its report.
The GitHub Action reviewdog/action-setup@v1 was compromised in an incident tracked as CVE-2025-30154. Multiple Reviewdog actions were affected, but the supplied report did not identify the timeframe boundaries or provide a complete list of affected actions.
Attackers compromised the third-party GitHub Action tj-actions/changed-files, tracked as CVE-2025-30066, potentially exposing workflow secrets through action logs. More than 23,000 repositories used the action, but the number that experienced secret exposure was not established.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.