PatchSiren cyber security CVE debrief
CVE-2025-30154 reviewdog CVE debrief
CVE-2025-30154 is a GitHub Actions supply-chain issue affecting reviewdog/action-setup and is listed in CISA’s Known Exploited Vulnerabilities catalog. Because CISA has assigned a mitigation due date and directs organizations to follow vendor guidance or stop using the product if mitigations are unavailable, this should be treated as an urgent CI/CD risk.
- Vendor
- reviewdog
- Product
- action-setup GitHub Action
- CVSS
- HIGH 8.6
- CISA KEV
- Listed
- Original CVE published
- 2025-03-24
- Original CVE updated
- 2025-03-24
- Advisory published
- 2025-03-24
- Advisory updated
- 2025-03-24
Who should care
Security and DevOps teams that use reviewdog/action-setup in GitHub workflows, especially repository owners, CI/CD platform operators, and supply-chain risk owners responsible for third-party Actions.
Technical summary
The supplied corpus identifies CVE-2025-30154 as an "Embedded Malicious Code" vulnerability in reviewdog/action-setup GitHub Action. CISA has added it to KEV, which indicates it is a known exploited vulnerability and requires prompt mitigation. The supplied materials do not include a CVSS score or deeper technical mechanism details.
Defensive priority
Urgent
Recommended defensive actions
- Inventory repositories and workflows that reference reviewdog/action-setup and determine where it is in use.
- Follow the vendor and CISA mitigation guidance immediately; replace, update, or discontinue the Action if a safe mitigation is not available.
- Apply least-privilege settings for GitHub Actions tokens and workflow permissions in affected repositories.
- Review workflow execution history and related CI/CD logs for unexpected behavior around use of the Action.
- Track the official CVE, NVD, and CISA KEV entries for any updated remediation guidance or status changes.
Evidence notes
CVE and source records are both dated 2025-03-24 in the supplied corpus. CISA KEV lists reviewdog/action-setup as a known exploited vulnerability, sets a due date of 2025-04-14, and states: "Apply mitigations as set forth in the CISA instructions linked below... or discontinue use of the product if mitigations are unavailable." The supplied corpus does not include a CVSS score.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-30154 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-30154
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-30154 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30154
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.