← Back to browse · API

CVE-2025-30066

Severity
HIGH
CVSS
8.6
EPSS
0.72391
Risk score
84.74
CISA KEV
Yes
PoC
No
Published
2025-03-18
Modified
2025-03-18
First seen
2026-08-07
Aliases
EUVD-2025-6565, GHSA-MRRH-FWG8-R2C3
Products
tj-actions:changed-files 1 <46, tj-actions:changed-files GitHub Action
Sources
euvd EUVD-2025-6565
cisa.gov CVE-2025-30066

Description

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

References