CVE-2025-30154: reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
Summary
reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs.
Other reviewdog actions that use reviewdog/action-setup@v1 would also be compromised, regardless of version or pinning method: - reviewdog/action-shellcheck - reviewdog/action-composite-template - reviewdog/action-staticcheck - reviewdog/action-ast-grep - reviewdog/action-typos
Details
Malicious commit: https://github.com/reviewdog/action-setup/commit/f0d342d fix/retag via version upgrade: https://github.com/reviewdog/action-setup/commit/3f401fe
See the detailed report from Wiz Research: Wiz Blog Post and reviewdog maintainer annoucement: reviewdog #2079
Other sources
reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.
— CISA
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use reviewdog/action-setup@v1 that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
reviewdog/action-setupto a version that resolves this vulnerability.Fixed in v1Patch 3f401fe - Upgrade
Upgrade
reviewdog/action-ast-grepto a version that resolves this vulnerability.Fixed in v1Patch 3f401fe - Upgrade
Upgrade
reviewdog/action-composite-templateto a version that resolves this vulnerability.Fixed in v1Patch 3f401fe - Upgrade
Upgrade
reviewdog/action-shellcheckto a version that resolves this vulnerability.Fixed in v1Patch 3f401fe - Upgrade
Upgrade
reviewdog/action-staticcheckto a version that resolves this vulnerability.Fixed in v1Patch 3f401fe - Upgrade
Upgrade
reviewdog/action-typosto a version that resolves this vulnerability.Fixed in v1Patch 3f401fe - Operational
Check GitHub Actions workflow logs from March 11, 2025 between 18:42 and 20:31 UTC for any dumped secrets, and rotate any credentials/secrets that may have been exposed before/while using reviewdog/action-setup@v1 (and the other affected reviewdog actions that depend on it).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30154?
CVE-2025-30154 has a critical severity level due to the exposure of sensitive secrets in GitHub Actions Workflow Logs.
How do I fix CVE-2025-30154?
To fix CVE-2025-30154, update to the latest non-compromised version of the reviewdog/action-setup.
What versions of reviewdog are affected by CVE-2025-30154?
CVE-2025-30154 affects version 1 of the reviewdog/action-setup and other related actions using this compromised version.
What is the impact of CVE-2025-30154?
The impact of CVE-2025-30154 includes the potential exposure of sensitive information such as tokens and secrets in workflow logs.
When was CVE-2025-30154 first discovered?
CVE-2025-30154 was compromised on March 11, 2025, between 18:42 and 20:31 UTC.