Junglewise Threat Intelligence

CVE-2025-30066: tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

CVE-2025-30066 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2025-03-18

Executive brief

The tj-actions/changed-files GitHub Action was compromised by a threat actor who modified tags v1 through v45.0.7 to point to a malicious commit. The embedded malicious code (updateFeatures) allows remote attackers to exfiltrate secrets, such as AWS keys and GitHub PATs, by reading GitHub Actions workflow logs.

Affected products

  • tj-actions changed-files v1 through v45.0.7

Timeline

  • 2025-03-14: exploited: Malicious code injected into tags v1 through v45.0.7 by a threat actor.
  • 2025-03-18: disclosed: CVE-2025-30066 published.
  • 2025-03-18: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2025-03-19: patched: Version 46 and later are considered safe.