PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-30154 reviewdog CVE debrief

CVE-2025-30154 is a GitHub Actions supply-chain issue affecting reviewdog/action-setup and is listed in CISA’s Known Exploited Vulnerabilities catalog. Because CISA has assigned a mitigation due date and directs organizations to follow vendor guidance or stop using the product if mitigations are unavailable, this should be treated as an urgent CI/CD risk.

Vendor
reviewdog
Product
action-setup GitHub Action
CVSS
HIGH 8.6
CISA KEV
Listed
Original CVE published
2025-03-24
Original CVE updated
2025-03-24
Advisory published
2025-03-24
Advisory updated
2025-03-24

Who should care

Security and DevOps teams that use reviewdog/action-setup in GitHub workflows, especially repository owners, CI/CD platform operators, and supply-chain risk owners responsible for third-party Actions.

Technical summary

The supplied corpus identifies CVE-2025-30154 as an "Embedded Malicious Code" vulnerability in reviewdog/action-setup GitHub Action. CISA has added it to KEV, which indicates it is a known exploited vulnerability and requires prompt mitigation. The supplied materials do not include a CVSS score or deeper technical mechanism details.

Defensive priority

Urgent

Recommended defensive actions

  • Inventory repositories and workflows that reference reviewdog/action-setup and determine where it is in use.
  • Follow the vendor and CISA mitigation guidance immediately; replace, update, or discontinue the Action if a safe mitigation is not available.
  • Apply least-privilege settings for GitHub Actions tokens and workflow permissions in affected repositories.
  • Review workflow execution history and related CI/CD logs for unexpected behavior around use of the Action.
  • Track the official CVE, NVD, and CISA KEV entries for any updated remediation guidance or status changes.

Evidence notes

CVE and source records are both dated 2025-03-24 in the supplied corpus. CISA KEV lists reviewdog/action-setup as a known exploited vulnerability, sets a due date of 2025-04-14, and states: "Apply mitigations as set forth in the CISA instructions linked below... or discontinue use of the product if mitigations are unavailable." The supplied corpus does not include a CVSS score.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-30154 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-30154

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-30154 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30154

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.