CVE-2025-30066Active Exploitation(tj-actions / changed-files)

HIGHCVSS 8.6 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch tj-actions changed-files systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-08. Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-506

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • changed-files

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 6 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 5d ago at 1 mentions (2026-03-29); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
changed-files

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-29: 1Mentions · 2026-04-01: 1Mentions · 2026-04-24: 1Mentions · 2026-06-18: 1Mentions · 2026-06-19: 1Mentions · 2026-08-28: 1PoC Mentioned / Linked · 2026-08-28: 1Exploit Tool / Code · 2026-08-28: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-08-28: 1Patch / Workaround · 2026-06-19: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 103-2904-0104-2406-1806-1908-28
Signal classification3 categories
Active Exploitation
350.0%
General
233.3%
Disclosure
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-291
General1
2026-04-011
Active Exploitation1
2026-04-241
General1
2026-06-181
Disclosure1
2026-06-191
Active Exploitation1
2026-08-281
Active Exploitation1
Full discourse6 posts
  • s1r1us (mohan)@S1r1u5_
    General

    Doing some detection research, anyone have samples (or know a good source) for the malicious payloads from the Ultralytics (8.3.41/42/45/46), tj-actions/changed-files (CVE-2025-30066), and Nx s1ngularity incidents?

    Post summary

    The post is a simple request for malicious payload samples related to a CVE and other incidents, and does not provide or imply exploitation, patching, or technical details.

    100622.3K
    13.7K followersView on X
  • Amaresh Pelleti@amareswer
    Active Exploitation

    4/8 Security is where teams actually get burned. March 2025: someone repointed every tag of tj-actions/changed-files to code that dumped secrets into public build logs. 23,000+ repos ran it. CVE-2025-30066.

    Post summary

    Attackers repointed tj-actions/changed-files tags to malicious code that dumped secrets, affecting over 23 000 repos in March 2025, demonstrating widespread active exploitation of CVE‑2025‑30066.

    1000022
    52 followersView on X
  • 城咲子@情シスセキュリティ担当@jo_sekiko
    Active Exploitation

    CVE-2025-30066 CVSS 8.6 tj-actionsサプライチェーン攻撃。 23,000+リポジトリのCIログにシークレットをprint。 「AIが書いたworkflowだから安全」は通用しない。 AIは署名なしのActionsを平気で使う。 pin-by-SHA256必須。情シスの胃に優しくない現実。 #GitHubActions #CVE

    Post summary

    CVE-2025-30066, a supply‑chain flaw in GitHub Actions, has already caused secret leaks across thousands of repositories; 23,000+ CI logs expose credentials, underscoring the need to enforce SHA‑256 pinning to mitigate the issue.

    0000078
    4.3K followersView on X
  • 城咲子@情シスセキュリティ担当@jo_sekiko
    Disclosure

    GitHub ActionsとCopilot/Claude Codeで起きるシークレット漏洩4パターン - デバッグecho混入 - Comment-and-Control攻撃 - CVE-2025-30066(CVSS 8.6)サプライチェーン - CamoLeak CVE-2025-59145(CVSS 9.6) https://infomation-sytem-security.hatenablog.com/entry/github-actions-ai-secret-leak-patterns #GitHubActions #AIセキュリティ #情シス

    Post summary

    The blog post describes four secret‑leak patterns in GitHub Actions, including two supply‑chain CVEs with CVSS scores, but offers no proof‑of‑concept, exploit code, or patch information.

    00000234
    4.3K followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: 36-Month Supply Chain Campaign - CVE-2024-3094, CVE-2025-30066, CVE-2025-30154 targeting DevSecOps tools. 9 detections, 25 IOCs. https://intel.threadlinqs.com/#TL-2026-0310 #ThreatIntel #CyberSecurity #SupplyChain https://t.co/v6VlWmFXLa

    Post summary

    The post announces a supply‑chain campaign involving three CVEs, noting 9 detections and 25 IOCs, which signals that the vulnerabilities are being actively exploited in the wild.

    00000218
    16 followersView on X
  • Grok@grok
    General

    Yes, the claims match verified events: Coinbase outage Feb 12 2026 (API overload during volatility), GitHub supply chain attack on Coinbase March 2025 (CVE-2025-30066, remediated Mar 19), Binance Oct 10 2025 flash crash ($19B+ liquidations), and GitHub's 39M secret leaks in 2024. It means crypto trading infra has real systemic risks—outages when markets move fast, GitHub creds/supply chain as attack vectors, and dev practices exposing production secrets. Diversify platforms and self-custody helps.

    Post summary

    The post lists incidents involving several CVEs, including CVE‑2025‑30066, but provides no technical specifics, PoC, or active exploitation details.

    00000236
    8.5M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptj-actionschanged-files---

Explore more