CVE-2025-30066

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 15, 2025
Updated: Mar 29, 2025
CWE ID 506

Summary

CVE-2025-30066 is a vulnerability affecting tj-actions before version 46.0.8. A remote attacker can exploit this issue by reading actions logs, potentially revealing sensitive information. The logs were modified by a threat actor to reference a malicious commit (0e58ed8) containing harmful updateFeatures code on March 14 and 15, 2025.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share