theinfosecnews

CVE-2025-30154

CISA KEV

Published March 24, 2025 · Updated April 3, 2026

high
Official Description+

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

Affected Products

VendorProduct
reviewdogaction-setup GitHub Action

Patch Status

Patch by 2025-04-14

Recommended Actions

  1. Check if your systems use any of the affected products listed above.
  2. Apply vendor patches immediately if available.
  3. This vulnerability is in CISA's Known Exploited Vulnerabilities catalog — prioritize remediation.
  4. Monitor vendor advisories for updates and additional mitigations.
  5. Review logs for indicators of compromise related to CVE-2025-30154.