https://seclists.org/oss-sec/2025/q1/227: tj-action/changed-files GitHub action was compromised
Published Mar 19, 2025
·Updated
Affected Software
1 affected component
GitHub tj-action/changed-files=all tagged versions
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is critical due to unauthorized access and potential data breach.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, you should remove the compromised tj-action/changed-files GitHub action and revert to a secure version.
3
What are the risks associated with CVE-2025-XXXX?
CVE-2025-XXXX poses risks of code injection and exploitation of workflows using the compromised action.
4
When was CVE-2025-XXXX discovered?
CVE-2025-XXXX was discovered on March 14, 2025.
5
How can I check if I am affected by CVE-2025-XXXX?
You can check if you are affected by CVE-2025-XXXX by reviewing the usage of the tj-action/changed-files GitHub action in your repositories.