https://seclists.org/oss-sec/2025/q1/225: tj-action/changed-files GitHub action was compromised
Published Mar 15, 2025
·Updated
Affected Software
1 affected component
GitHub tj-action/changed-files=all tagged versions
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
CVE-2025-XXXX is considered critical due to the potential leakage of CI/CD secrets.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, remove the tj-action/changed-files dependency or revert to a previous safe version.
3
What are the risks associated with CVE-2025-XXXX?
The risks include unauthorized access to sensitive information, potentially compromising your development environment.
4
Who was affected by CVE-2025-XXXX?
All users of the tj-action/changed-files GitHub action are affected due to the malicious commit.
5
When was CVE-2025-XXXX published?
CVE-2025-XXXX was published on March 15, 2025.