---
id: CVE-2025-30066
title: >-
  tj-actions changed-files before 46 allows remote attackers to discover secrets
  by reading actions logs
summary: >-
  tj-actions changed-files before 46 allows remote attackers to discover secrets
  by reading actions logs. (The tags v1 through v45.0.7 were affected on
  2025-03-14 and 2025-03-15 because they were modified by a threat actor to
  point at comm…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-506
vendor: tj-actions
product: changed-files
affected:
  - changed-files <= 45.0.7
published: '2025-03-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T13:10:00.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30066'
references:
  - url: 'https://blog.gitguardian.com/compromised-tj-actions/'
    label: cve@mitre.org
  - url: 'https://github.com/chains-project/maven-lockfile/pull/1111'
    label: cve@mitre.org
  - url: 'https://github.com/espressif/arduino-esp32/issues/11127'
    label: cve@mitre.org
  - url: >-
      https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193
    label: cve@mitre.org
  - url: 'https://github.com/modal-labs/modal-examples/issues/1100'
    label: cve@mitre.org
  - url: 'https://github.com/rackerlabs/genestack/pull/903'
    label: cve@mitre.org
  - url: >-
      https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73/README.md?plain=1#L20-L28
    label: cve@mitre.org
  - url: 'https://github.com/tj-actions/changed-files/issues/2463'
    label: cve@mitre.org
  - url: 'https://github.com/tj-actions/changed-files/issues/2464'
    label: cve@mitre.org
  - url: 'https://github.com/tj-actions/changed-files/issues/2477'
    label: cve@mitre.org
  - url: 'https://news.ycombinator.com/item?id=43367987'
    label: cve@mitre.org
  - url: 'https://news.ycombinator.com/item?id=43368870'
    label: cve@mitre.org
  - url: >-
      https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised/
    label: cve@mitre.org
  - url: >-
      https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files-supply-chain-attack-cve-2025-30066/
    label: cve@mitre.org
  - url: >-
      https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463
    label: cve@mitre.org
  - url: >-
      https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
    label: cve@mitre.org
  - url: >-
      https://www.stream.security/post/github-action-supply-chain-attack-exposes-secrets-what-you-need-to-know-and-how-to-respond
    label: cve@mitre.org
  - url: >-
      https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack
    label: cve@mitre.org
  - url: >-
      https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-attack-cve-2025-30066
    label: cve@mitre.org
  - url: >-
      https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-github-action-cve-2025-30066
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-30066
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.72092
epssPercentile: 0.99415
kev: true
kevDateAdded: '2025-03-18'
kevDueDate: '2025-04-08'
kevRansomware: false
exploited: true
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool'
    - 'https://github.com/Super-Vulnerable-Org/compromised-action'
  checkedAt: '2026-09-27T10:33:33.868Z'
exploitAvailable: true
ingestedAt: '2026-09-24T13:43:25.656Z'
---

## Overview

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

## Affected

- `changed-files <= 45.0.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
