CVE-2025-30066
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Mar 15, 2025
Updated: Mar 29, 2025
CWE ID 506
Summary
CVE-2025-30066 is a vulnerability affecting tj-actions before version 46.0.8. A remote attacker can exploit this issue by reading actions logs, potentially revealing sensitive information. The logs were modified by a threat actor to reference a malicious commit (0e58ed8) containing harmful updateFeatures code on March 14 and 15, 2025.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Tj-actions