PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-30066 tj-actions CVE debrief

CVE-2025-30066 is a supply-chain security issue in the tj-actions/changed-files GitHub Action, described in the supplied corpus as an embedded malicious code vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-18, which means defenders should treat it as an urgent exposure and apply the referenced mitigations or discontinue use if mitigations are unavailable.

Vendor
tj-actions
Product
changed-files GitHub Action
CVSS
HIGH 8.6
CISA KEV
Listed
Original CVE published
2025-03-18
Original CVE updated
2025-03-18
Advisory published
2025-03-18
Advisory updated
2025-03-18

Who should care

Teams that maintain GitHub Actions workflows, DevSecOps and platform engineering groups, open-source maintainers, and any organization that depends on tj-actions/changed-files in CI/CD pipelines.

Technical summary

The supplied official records identify CVE-2025-30066 as malicious code embedded in the tj-actions/changed-files GitHub Action. The corpus does not provide a CVSS score or deeper exploit mechanics, but CISA classifies it as a known exploited vulnerability and directs affected users to apply mitigations per vendor guidance or stop using the product if mitigations cannot be applied.

Defensive priority

Urgent

Recommended defensive actions

  • Determine whether any repositories, reusable workflows, or automation pipelines depend on tj-actions/changed-files.
  • Follow the mitigation guidance referenced by CISA and the vendor official records.
  • If mitigations are not available in your environment, discontinue use of the affected action.
  • Apply CISA BOD 22-01 guidance where the affected workflow is used in cloud services.
  • Track the official CVE and NVD records for updates and any additional remediation guidance.

Evidence notes

This debrief uses only the supplied CISA KEV metadata and the official CVE/NVD links included in the corpus. The corpus explicitly labels the issue as an embedded malicious code vulnerability for tj-actions/changed-files, marks it as a Known Exploited Vulnerability, and provides a mitigation deadline of 2025-04-08. No CVSS score or exploit narrative was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-30066 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-30066

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-30066 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-30066

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.