Find and Fix CVE-2025-30066, Compromised GitHub Actions Leading to Credential Leaks
ID: 45a259cf-52e3-5dee-8de4-5b43d541fb09
STIX ID: report--45a259cf-52e3-5dee-8de4-5b43d541fb09
Feed Name: Checkmarx Zero
On March 14, 2025 Step Security disclosed that multiple GitHub Actions (including tj-actions/changed-files, tj-actions/eslint-changed-files and several reviewdog Actions) were compromised and contain code that exposes secrets and sensitive information in GitHub Actions run logs (tracked as CVE-2025-30066). The report urges organizations to audit workflow YAML files, replace affected actions (Step Security provides a drop-in replacement for tj-actions/changed-files), restrict repository access while remediating, scan run logs for leaked secrets using provided detection tools, and rotate any exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
