logo

Find and Fix CVE-2025-30066, Compromised GitHub Actions Leading to Credential Leaks

ID: 45a259cf-52e3-5dee-8de4-5b43d541fb09

STIX ID: report--45a259cf-52e3-5dee-8de4-5b43d541fb09

Feed Name: Checkmarx Zero

Threat Score
85/100

Date Published: 2025-03-18

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

On March 14, 2025 Step Security disclosed that multiple GitHub Actions (including tj-actions/changed-files, tj-actions/eslint-changed-files and several reviewdog Actions) were compromised and contain code that exposes secrets and sensitive information in GitHub Actions run logs (tracked as CVE-2025-30066). The report urges organizations to audit workflow YAML files, replace affected actions (Step Security provides a drop-in replacement for tj-actions/changed-files), restrict repository access while remediating, scan run logs for leaked secrets using provided detection tools, and rotate any exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.