What is CVE-2025-30066?
This vulnerability in the GitHub Action tj-actions/changed-files enables supply chain attacks by allowing remote attackers to expose CI/CD secrets through build logs. Projects using this action are affected and should immediately update or switch to a temporary alternative.
Azərbaycanca: GitHub-un tj-actions/changed-files aksiyasında aşkarlanan bu boşluq təchizat zəncirinə qarşı hücumlara şərait yaradır. O, uzaqdan hücum edən şəxslərə build log-lar vasitəsilə CI/CD məxfi məlumatlarını ələ keçirməyə imkan verir. Bu aksiyadan istifadə edən layihələrdə təcili yenilənmə və ya müvəqqəti alternativlərə keçid tövsiyə olunur.
Related CVEs
link basis: shared vendor: GitHub
FAQ2
Which GitHub Action is affected by CVE-2025-30066?
This vulnerability was discovered in the tj-actions/changed-files action.
What can attackers gain access to by exploiting CVE-2025-30066?
Remote attackers can expose CI/CD secrets through build logs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.