CVE-2025-30154
CVSS 3.1 Score 8.6 of 10 (high)
Details
Summary
CVE-2025-30154 is a vulnerability affecting the GitHub action 'reviewdog/action-setup'. On March 11, 2025, between 18:42 and 20:31 UTC, the action was compromised, resulting in malicious code being added. This code dumps exposed secrets to GitHub Actions Workflow Logs. Any reviewdog actions that depend on 'reviewdog/action-setup@v1', including 'reviewdog/action-shellcheck', 'reviewdog/action-composite-template', 'reviewdog/action-staticcheck', 'reviewdog/action-ast-grep', and 'reviewdog/action-typos', were also compromised, regardless of version or pinning method.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.