PatchSiren cyber security CVE debrief
CVE-2025-30066 tj-actions CVE debrief
CVE-2025-30066 is a supply-chain security issue in the tj-actions/changed-files GitHub Action, described in the supplied corpus as an embedded malicious code vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-18, which means defenders should treat it as an urgent exposure and apply the referenced mitigations or discontinue use if mitigations are unavailable.
- Vendor
- tj-actions
- Product
- changed-files GitHub Action
- CVSS
- HIGH 8.6
- CISA KEV
- Listed
- Original CVE published
- 2025-03-18
- Original CVE updated
- 2025-03-18
- Advisory published
- 2025-03-18
- Advisory updated
- 2025-03-18
Who should care
Teams that maintain GitHub Actions workflows, DevSecOps and platform engineering groups, open-source maintainers, and any organization that depends on tj-actions/changed-files in CI/CD pipelines.
Technical summary
The supplied official records identify CVE-2025-30066 as malicious code embedded in the tj-actions/changed-files GitHub Action. The corpus does not provide a CVSS score or deeper exploit mechanics, but CISA classifies it as a known exploited vulnerability and directs affected users to apply mitigations per vendor guidance or stop using the product if mitigations cannot be applied.
Defensive priority
Urgent
Recommended defensive actions
- Determine whether any repositories, reusable workflows, or automation pipelines depend on tj-actions/changed-files.
- Follow the mitigation guidance referenced by CISA and the vendor official records.
- If mitigations are not available in your environment, discontinue use of the affected action.
- Apply CISA BOD 22-01 guidance where the affected workflow is used in cloud services.
- Track the official CVE and NVD records for updates and any additional remediation guidance.
Evidence notes
This debrief uses only the supplied CISA KEV metadata and the official CVE/NVD links included in the corpus. The corpus explicitly labels the issue as an embedded malicious code vulnerability for tj-actions/changed-files, marks it as a Known Exploited Vulnerability, and provides a mitigation deadline of 2025-04-08. No CVSS score or exploit narrative was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-30066 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-30066
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-30066 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30066
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.