CVE-2025-30066 | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
- 🔗 github.com/github/docs/blob/962a1c8dccb8c0f66548b324…
- 🔗 github.com/tj-actions/changed-files/issues/2463
- 🔗 www.stepsecurity.io/blog/harden-runner-detection-tj-actions-c…
- 🔗 semgrep.dev/blog/2025/popular-github-action-tj-action…
- 🔗 news.ycombinator.com/item
- 🔗 web.archive.org/web/20250315060250/https://github.com/tj-…
- 🔗 news.ycombinator.com/item
- 🔗 github.com/rackerlabs/genestack/pull/903
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-24 | 2026-10-08 |
|---|---|---|
| ≥90 % | 484 | 342 |
| ≥50 % | 1436 | 1061 |
| ≥10 % | 16 | 2 |
| <10 % | 30 | 562 |
CVE-2025-30066 | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit
Noch keine Analyse zu CVE-2025-30066
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.