CVE-2025-30154

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 19, 2025
Updated: Mar 29, 2025
CWE ID 506

Summary

CVE-2025-30154 is a vulnerability affecting the GitHub action 'reviewdog/action-setup'. On March 11, 2025, between 18:42 and 20:31 UTC, the action was compromised, resulting in malicious code being added. This code dumps exposed secrets to GitHub Actions Workflow Logs. Any reviewdog actions that depend on 'reviewdog/action-setup@v1', including 'reviewdog/action-shellcheck', 'reviewdog/action-composite-template', 'reviewdog/action-staticcheck', 'reviewdog/action-ast-grep', and 'reviewdog/action-typos', were also compromised, regardless of version or pinning method.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share