---
cve: "CVE-2025-30066"
severity: "HIGH"
cvss: 8.6
epss: "69.6%"
vendor: "tj-actions"
kev: true
exploited: true
published: "2025-03-15 06:15:12"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T06:57:33+02:00"
---

# CVE-2025-30066

> 8.6 HIGH · ⚠️ CISA KEV (539 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- ed68ef82c095e0d48ec87eccea555d944a631a4c (Commit)

## Referenzen

- <https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193>
- <https://github.com/tj-actions/changed-files/issues/2463>
- <https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised>
- <https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/>
- <https://news.ycombinator.com/item?id=43368870>
- <https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463>
- <https://news.ycombinator.com/item?id=43367987>
- <https://github.com/rackerlabs/genestack/pull/903>
- <https://github.com/chains-project/maven-lockfile/pull/1111>
- <https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files-supply-chain-attack-cve-2025-30066/>
- <https://github.com/espressif/arduino-esp32/issues/11127>
- <https://github.com/modal-labs/modal-examples/issues/1100>
- <https://github.com/tj-actions/changed-files/issues/2464>
- <https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73/README.md?plain=1#L20-L28>
- <https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-30066) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
