CVE-2025-30154: reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

Published Mar 19, 2025
·
Updated

Summary

reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs.

Other reviewdog actions that use reviewdog/action-setup@v1 would also be compromised, regardless of version or pinning method: - reviewdog/action-shellcheck - reviewdog/action-composite-template - reviewdog/action-staticcheck - reviewdog/action-ast-grep - reviewdog/action-typos

Details

Malicious commit: https://github.com/reviewdog/action-setup/commit/f0d342d fix/retag via version upgrade: https://github.com/reviewdog/action-setup/commit/3f401fe

See the detailed report from Wiz Research: Wiz Blog Post and reviewdog maintainer annoucement: reviewdog #2079

Other sources

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

CISA

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use reviewdog/action-setup@v1 that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

NVD

Affected Software

14 affected components
reviewdog action-setup>=v1<=v1
reviewdog action-shellcheck
reviewdog action-composite-template
reviewdog action-staticcheck
reviewdog action-ast-grep
reviewdog action-typos
reviewdog action-setup GitHub Action
reviewdog action-ast-grep<1.26.2
reviewdog action-composite-template<0.20.2
reviewdog action-setup=1
reviewdog action-shellcheck<1.29.2
reviewdog action-staticcheck<1.26.2
reviewdog action-typos<1.17.2
actions/reviewdog/action-setup=1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade reviewdog/action-setup to a version that resolves this vulnerability.

    Fixed in v1Patch 3f401fe
  2. Upgrade

    Upgrade reviewdog/action-ast-grep to a version that resolves this vulnerability.

    Fixed in v1Patch 3f401fe
  3. Upgrade

    Upgrade reviewdog/action-composite-template to a version that resolves this vulnerability.

    Fixed in v1Patch 3f401fe
  4. Upgrade

    Upgrade reviewdog/action-shellcheck to a version that resolves this vulnerability.

    Fixed in v1Patch 3f401fe
  5. Upgrade

    Upgrade reviewdog/action-staticcheck to a version that resolves this vulnerability.

    Fixed in v1Patch 3f401fe
  6. Upgrade

    Upgrade reviewdog/action-typos to a version that resolves this vulnerability.

    Fixed in v1Patch 3f401fe
  7. Operational

    Check GitHub Actions workflow logs from March 11, 2025 between 18:42 and 20:31 UTC for any dumped secrets, and rotate any credentials/secrets that may have been exposed before/while using reviewdog/action-setup@v1 (and the other affected reviewdog actions that depend on it).

Event History

Feb 19, 2024
News Published
via The Register·01:29 AM
Mar 11, 2024
News Published
via The Register·04:28 AM
Jun 17, 2024
News Published
via The Register·01:59 AM
Nov 25, 2024
News Published
via The Register·01:30 AM
Feb 17, 2025
News Published
via The Register·02:25 AM
Mar 16, 2025
News Published
via The Register·10:58 PM
Mar 19, 2025
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:19 PM
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 24, 2025
Known Exploited
via CISA·12:00 AM
Mar 30, 2025
News Published
via The Register·10:45 PM
Feb 8, 2026
News Published
via The Register·10:25 PM
News Published
via The Register·10:28 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-30154?

CVE-2025-30154 has a critical severity level due to the exposure of sensitive secrets in GitHub Actions Workflow Logs.

2

How do I fix CVE-2025-30154?

To fix CVE-2025-30154, update to the latest non-compromised version of the reviewdog/action-setup.

3

What versions of reviewdog are affected by CVE-2025-30154?

CVE-2025-30154 affects version 1 of the reviewdog/action-setup and other related actions using this compromised version.

4

What is the impact of CVE-2025-30154?

The impact of CVE-2025-30154 includes the potential exposure of sensitive information such as tokens and secrets in workflow logs.

5

When was CVE-2025-30154 first discovered?

CVE-2025-30154 was compromised on March 11, 2025, between 18:42 and 20:31 UTC.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203